Hardware wallet maker Trezor has alerted customers after a security incident at its email provider, Brevo, led to a large-scale phishing campaign aimed at crypto users.
According to Trezor, attackers used access to Brevo accounts to send roughly 347,000 fraudulent emails that appeared to come from the company. The messages included a malicious link designed to push recipients toward a fake app requesting their wallet backup password.
Trezor said the issue did not affect its wallets, products, or account systems. Brevo stated that the attackers reached 138 accounts and were able to distribute messages more broadly than intended because access controls were not properly limited.
The incident follows a separate breach involving a shipping partner, which exposed customer contact details. Trezor says it is now reviewing vendor relationships and reminding users to stay alert to suspicious messages that reference wallet security.
As digital assets become more mainstream, stronger protections across the entire service chain may shape the next phase of trust in crypto infrastructure.