A security flaw in Brevo's email marketing platform enabled attackers to send phishing emails to 347,000 Trezor hardware wallet subscribers, potentially compromising one of crypto's most widely-used self-custody solutions.

Trezor disclosed the breach to Cointelegraph, confirming that phishing messages reached its subscriber list after attackers exploited a login vulnerability in Brevo, the email service provider managing Trezor's communications. The hardware wallet manufacturer now treats every exposed email address as "known to the attacker and possibly reusable for phishing," according to the statement.

The scale of this incident matters. Trezor claims over 1.5 million active users globally, making 347,000 compromised addresses roughly 23 percent of its active base. These are not random email addresses. They belong to people who actively purchased or use Trezor hardware wallets, marking them as high-value targets for future attacks. Attackers now possess a confirmed list of crypto asset holders.

Phishing remains the leading attack vector against hardware wallet users. Despite Trezor's physical device security, its strength collapses when users receive convincing emails directing them to fake recovery seed entry screens or fraudulent wallet restoration portals. The attacker's goal was straightforward: trick users into voluntarily handing over private keys or seed phrases through social engineering.

Brevo's login flaw represents a third-party risk that even security-conscious users cannot fully control. Trezor did not create the vulnerability, but it trusted Brevo with direct access to its user database and email sending infrastructure. When that trust breaks, consequences cascade downstream to all users.

Trezor's response involves treating affected addresses as permanently compromised. The company likely plans heightened monitoring and may have notified users through secondary channels outside the compromised email list. However, the damage is done. Attackers now possess a validated list of crypto-aware individuals to target with future campaigns, whether through email, SMS, phone calls, or social media.

This incident highlights a persistent tension in crypto security. Hardware wallets provide robust protection against remote theft, but they operate within ecosystems that depend on centralized services: email providers, firmware update servers, customer support channels, and recovery documentation. Compromise any of these touchpoints and the hardware wallet's isolation vanishes.

Brevo has not publicly disclosed details about the nature or duration of the vulnerability. The timeline matters enormously. If the flaw remained open for weeks or months, attackers potentially sent multiple waves of phishing emails or harvested data at different dates. If it lasted hours, damage control becomes marginally more effective.

For Trezor users, immediate steps include: verifying all wallet recovery seeds remain private, enabling additional authentication on email accounts, watching for suspicious password reset attempts, and ignoring any emails claiming to be from Trezor that request sensitive information. Legitimate wallet providers never ask for seed phrases via email.

This breach underscores why hardware wallet users must maintain vigilance beyond their physical devices. The security chain extends through every service that touches user data, and weakest links receive the most attention from attackers. Brevo's vulnerability proved exactly that.