FILTERED RESULTS
FILTERS
Ads Top
DARK MODE
CHART
MCap $2.9T +0.4%24h Vol $101.1B -35%Fear & Greed 71/100Alts Index 57/100
BTC.D 58.4% +0.1%Stable.D 9.2% 0%ETH.D 11.3% -0.1%Others.D 21.1% 0%
SOON$0.5109+30.62%•STONK$0.2919+22.27%•QNT$298.93+18.94%•NIGHT$0.0365+14.17%•PROM$6.587+12.02%•TRAC$0.4133+11.34%•KSM$5.193+10.94%•DEEP$0.0234+10.17%•CAP$0.0646+10.03%•RAY$2.064+9.92%•
AI$0.1811-13.33%•TIBBIR$0.2944-12.76%•BTW$1.158-11.27%•BR$0.7593-10.7%•LIT$4.019-9.25%•BP$1.207-8.52%•SKY$0.0788-7.14%•SYRUP$0.2275-7.09%•MARSCOIN$0.1361-6.59%•AAVE$160.09-5.79%•
Top movers 24h
    Filters
      Coins
      Sentiment
      Impact
      Search
      FILTERED RESULTS

        

      Upgrade your plan
      Dashboard

      Trezor Reported a Breach at a Third-party Email Provider Amid a Phishing Attack

      • Attackers used Trezor’s mailing infrastructure to distribute phishing emails.
      • BitBox and CoinTracking faced similar attacks.
      • Independent researchers link the incidents to Brevo’s infrastructure, but there is no official confirmation from the provider as of the time of writing.

      On September 9, 2026, hardware wallet maker Trezor reported that a third-party email provider had been compromised. Attackers sent emails posing as the company with the subject line “Critical Security Alert: STM32 Entropy Vulnerability,” claiming there was a critical vulnerability in the hardware wallets.

      Trezor stressed that the message is not related to the company and is a phishing attempt. The team took down the domain used in the attack and launched an investigation, including into how the attackers gained access to the mailing infrastructure. The company did not disclose the name of the third-party provider. 

      According to recipients, the malicious emails looked especially convincing because they came from help@trezor.io, and the headers referenced the domain mailing.trezor.io. 

      The messages also passed standard SPF, DKIM, and DMARC checks. As a result, the mailing could appear authentic to the email service despite the fraudulent content. 

      The email claimed that a flaw in STM32 microcontrollers could allegedly reduce the reliability of generated seed phrases. Recipients were urged to follow a link and check their device. On the phishing pages, attackers could request an xPub or even the recovery phrase. 

      Incrypted’s editorial team reached out to Trezor for comment regarding the incident. We will update the article when and if we receive a response.

      Trezor Not the Only Victim of Attackers

      Hardware wallet maker BitBox confirmed the distribution of phishing emails and later published the results of a preliminary review. According to the team, the email distribution service provider was very likely compromised. 

      BitBox also said that several other crypto companies were targeted as well, and they likely used the same provider.

      In BitBox’s case, attackers sent an email with the subject line “Critical Security Alert: Microcontroller Entropy Bug Identified.” The company warned subscribers, contacted the service provider, and reported the phishing domains. At the time the statement was published, most of the malicious links had already been taken down.

      Another publicly identified target was crypto portfolio tracking platform CoinTracking. Users received emails from support@cointracking.info with the subject line “Data Breach Notice: Please refresh API Keys as soon as possible.” The messages attempted to persuade potential victims to refresh their API keys via a third-party resource. 

      CoinTracking also posted a warning about phishing emails circulating. The company noted that the fraudulent messages lead to websites requesting credentials for access to crypto exchanges, and emphasized that the service’s staff never ask for login details or API keys with trading and withdrawal permissions. 

      As a result, at the time of writing, at least three brands are publicly known to have been impersonated in similar messages: Trezor, BitBox, and CoinTracking. 

      A likely common link may be the email marketing platform Brevo, previously known as Sendinblue. Researchers found a shared DKIM configuration across the Trezor and BitBox domains, and industry sources reported the creation of unauthorized API keys in affected Brevo accounts. 

      However, neither Trezor nor BitBox named the provider in their initial statements, so it is still premature to talk about a confirmed breach of Brevo’s core infrastructure. 

      The initial attack vector also remains unclear. It could have been an incident on the service’s side, or attackers gaining access to individual client accounts and then creating API keys. As of writing, no public statement from Brevo that would definitively clarify this issue could be found. 

      Notably, a similar scheme was already used against Trezor customers in August 2026. At the time, attackers also sent out warnings about an allegedly critical vulnerability related to entropy and seed phrase generation. 

      Trezor said at the time that attackers could have combined information from various data leaks at cryptocurrency services. This incident is different, however, in that the phishing messages, based on the available data, were distributed via legitimate email marketing infrastructure. 

      At this point, there is no confirmation that the vulnerability described in the emails actually exists in Trezor or BitBox devices. The companies recommend that users do not click links in suspicious emails and, under no circumstances, enter their recovery phrase on websites.

      Сообщение Trezor Reported a Breach at a Third-party Email Provider Amid a Phishing Attack появились сначала на INCRYPTED.


      Source: Incrypted
      .

      Terra Founder Do Kwon Sentenced to 15 Years in Prison for Fraud