Hundreds of thousands of Trezor users are at renewed risk after the hardware wallet maker confirmed hackers used a breach at marketing vendor Brevo to send 347,000 phishing emails that pose as official messages. Trezor says the malicious link in those messages installs an app that asks victims for their wallet backup password, and with that password an attacker can irreversibly take funds from a wallet on the public blockchain.

Brevo reported the intruders were able to access 138 Brevo accounts and send the mass volume of phishing messages. The company said attackers exploited a flaw so the access was "not properly scoped," and that access was "wrongly granted" to all organisations reachable by the compromised accounts. Brevo's description indicates the breach let the attackers use legitimate vendor infrastructure to appear authentic to recipients.

Trezor emphasised its core systems were not breached, saying none of its products, wallets, or account system were affected. Still, the company warned that customers' email addresses could be used again for future phishing and said it is re-evaluating relationships with vendors used for communications and fulfilment.

The Brevo incident follows a recent security problem linked to the wallet maker's shipping partner, ShipMonk, which exposed the names, phone numbers, email addresses, and postal addresses of at least 81,000 customers. That earlier disclosure raised risks beyond online fraud; Trezor flagged the potential for targeted physical attacks and so-called wrench attacks, and the company reported follow-on scams including letters with QR codes that led victims to fake pages designed to harvest wallet passwords.

For customers the immediate threat is social engineering delivered through a channel that looks legitimate. Trezor's alerts and the technical details Brevo disclosed show how compromises at third-party vendors can let attackers bypass some email-origin checks and scale phishing quickly. The company has urged users to treat unexpected security notices with scepticism, and to protect their recovery phrases and backup passwords offline.

How vendors change their access controls and how Trezor tightens vendor oversight will determine whether similar campaigns can be prevented. In the near term, the incident signals that owners of hardware wallets remain attractive targets because a single stolen backup password leads directly to a loss of funds.