The second Trezor security incident of September is not a data breach in the sense the first one was. It is a delivery breach: the attacker did not steal Trezor’s customer data, they borrowed Trezor’s voice. At approximately 21:30 Central European Summer Time — 19:30 UTC — on Wednesday 9 September, an email with the subject line “Critical Security Alert: STM32 Entropy Vulnerability” was sent to about 347,000 addresses on Trezor’s newsletter list, according to details Trezor gave The Crypto Times on Thursday. It displayed the sender name “Trezor Security,” used help@trezor.io in the From field, and carried a Return-Path at mailing.trezor.io. Because it travelled through Trezor’s own newsletter infrastructure — the company’s account at Brevo, the third-party provider it uses for email — it passed SPF, DKIM and DMARC, the three checks that mail clients use to decide whether a message is really from the domain it claims. The body alleged a factory defect in the STM32 microcontroller under which roughly one device in four produced weak 40-bit seeds, and directed recipients to a page hosted at r.mailing.trezor.io; some variants of that page asked users to verify their xPub. Trezor has published no advisory matching the claim and says it is false.

Trezor’s timeline, as given to The Crypto Times: an internal security alert flagged the send shortly after it went out; staff reviewed the sending logs on the Brevo account and confirmed the messages had left through it; a public warning went up on X at 20:37 UTC — 67 minutes after the send — saying the third-party provider had been breached and telling recipients not to click; a follow-up at 22:20 UTC repeated that the provider had been compromised. The phishing domain was taken down at the DNS level within 20 minutes of detection, which Trezor says stopped the link working for later recipients. The Brevo account has been disconnected, Trezor says it emailed every recipient about the risk, added warning banners to trezor.io and Trezor Suite, and has disabled its email-sending function. Trezor told the outlet the Brevo account held only opt-in newsletter addresses — no passwords, no wallet data, no other personal information — that it cannot confirm whether the list was exported, and that it is treating all 347,000 addresses as known to the attacker until Brevo says otherwise.

Not only Trezor

The incident reaches past one company. Bitcoin.com News reported on Thursday that BitBox, the Swiss hardware-wallet maker, said on X that a phishing message had reached its subscribers, that its preliminary investigation pointed to its newsletter provider, and that “multiple bitcoin companies” had been targeted and appeared to share the same provider; and that CoinTracking, the portfolio and tax platform, named Brevo as the provider behind a fake message to its customers headed “Data Breach Notice: Please refresh API Keys as soon as possible.” BitBox said most of the phishing links were already down when it issued its statement and that its investigation remained active. Three companies, three different phishing lures, one provider named by two of them, Trezor and CoinTracking, with BitBox saying the targeted companies appeared to share one: the desk treats it as a single campaign against Brevo customers in the bitcoin industry until one of the three says otherwise.

What the lure was designed to extract is worth reading precisely. Trezor devices generate their seed on the device; the company does not hold seeds or backups and its statement repeats, as it did in August, that any message asking for a recovery phrase or backup is a scam. The STM32 story was built to make that rule feel inapplicable — if the device itself is defective, the reasoning goes, then checking the seed is the responsible thing to do — and the variants that asked for an xPub were after something a cautious user might consider harmless. An extended public key does not spend coins; it does reveal every address a wallet will ever generate and therefore its entire balance and history, which is exactly the information a follow-on attacker needs to decide which of 347,000 addresses is worth a targeted approach. Trezor’s statement was careful on the point: clicking the link “does not mean a user was compromised.” Entering a seed on the page would mean exactly that.

Scored on Field Guide #43

Field Guide #43, written on Sunday when the ShipMonk breach reached about 80,000 customers, put five questions to any hardware-wallet breach notice. Applied here: Who held the data and why? Brevo, a newsletter provider, held opt-in email addresses because sending newsletters requires them; that is a narrower and more defensible dataset than the shipping contractor’s names and home addresses. Which fields leaked? Possibly none: Trezor says it cannot confirm export. Functionally, the attacker demonstrated the ability to send to the list, which for phishing purposes is as good as having it. The retention claim, and how to test it. There is no retention claim to test this time; the failure was access to a live account, not a kept copy of a dead one. Phishing risk versus physical risk. This incident is pure phishing risk, and it has already been realised rather than merely created; it adds no physical risk of its own, but a user who is on both lists — the ShipMonk set with a home address and the Brevo set with an email — is now reachable by two channels with a consistent story. What to do this weekend. The guide’s answer stands unchanged: no seed, no passphrase and no xPub goes into a web page, whatever the sender field says, because Wednesday proved that the sender field can be correct and the message still be hostile.

One thing the guide did not anticipate is the authentication point, and it belongs in the next revision. Guide #43 told readers to check the sending domain. Wednesday’s email would have passed that check, and every automated one, because the domain was real and the account behind it was the compromised asset. The usable rule is narrower: a security alert from a hardware-wallet maker that asks you to do anything with your seed, backup or keys is a phishing email regardless of where it came from, because no legitimate alert from Trezor, BitBox, Coldcard or anyone else will ever ask for those. Provenance is necessary; it is no longer sufficient.

Markers

The two Trezor markers set on Sunday are unaffected in their terms: R1 (the ShipMonk customer count revised up again by 30 September) and S1 (the Anonymous Delivery option live in at least one EU country by 30 September) remain open. The desk adds one from today. AD1: Trezor publishes its findings on how the Brevo account was accessed — the “we will publish what we find” of Thursday’s statement — by Wednesday 30 September. The finding that matters is whether the access came through Brevo’s systems, in which case every Brevo customer in the industry has the same exposure, or through Trezor’s own credentials for the account, in which case the lesson is the older one about who holds the keys to the megaphone.

Trezor’s statement to The Crypto Times, in its own words: “Trezor devices, Trezor Suite, and Trezor’s own systems were not involved. Trezor does not hold wallet backups and never asks for one. Any message asking for a recovery phrase or backup is a scam.” The desk’s Sunday reporting on the ShipMonk breach is here; the earlier Coldcard security cluster is indexed in the Reading Room.

Sources: The Crypto Times, “Trezor Details Brevo Breach Behind Fake Security Alert,” 10 September 2026 (statement and timeline supplied by Trezor to that outlet); Bitcoin.com News, “Hackers Hijack Trezor, Bitbox Emails to Target Crypto Users,” 10 September 2026; posts on X by @Trezor (9 September 20:37 UTC), @BitBoxSwiss and @Coin_Tracking as rendered by those outlets. Times given in CEST by Trezor are converted to UTC by the desk (CEST = UTC+2).

Method: prices, funding, open interest, basis and on-chain figures in this article are pulled directly by Bitcoin Mastery at the timestamp stated — Bitstamp BTC/USD daily candles for closes, Binance BTCUSDT spot and USDT-margined perpetual for intraday, open interest, funding and account ratios, Binance COIN-M quarterly contracts for basis, mempool.space for difficulty, hashrate, pool shares, fees and individual Bitcoin transactions, blockstream.info’s Liquid API for sidechain block heights, hashes, timestamps and transaction counts, alternative.me for the Fear & Greed series, Farside Investors’ table for ETF flows and US Treasury CMT par yields for rates. Where a third-party figure is cited we name the source and its date; where two sources disagree we print both. Every streak or extreme figure is published with the first date of its series in the same sentence.

Disclaimer: This article is for informational purposes only and does not constitute investment advice. Cryptocurrencies are volatile and you can lose money. Nothing here is a recommendation to buy or sell any security, digital asset or exchange-traded fund, including MSTR, L-BTC or HYPE. Do your own research and consult a licensed financial advisor before making investment decisions.