The digital asset sector was rattled by a sophisticated phishing campaign on September 9, 2026, primarily targeting hardware wallet users. Major industry players, such as Trezor, BitBox, and CoinTracking, saw their official communication channels hijacked by cybercriminals. The attackers orchestrated a wave of fraudulent emails, alerting customers to a fabricated technical vulnerability involving STM32 chips, in an attempt to trick them into revealing their recovery phrases—the only key required to drain their cryptocurrency accounts.
The effectiveness of this attack relied on the direct compromise of Brevo, the email service provider used by these companies. By infiltrating the platform, the hackers bypassed standard security protocols like SPF, DKIM, and DMARC. Since the messages legitimately originated from Brevo servers, user spam filters failed to detect any anomalies, granting the emails absolute credibility. According to initial estimates, approximately 2,500 people took the bait out of a total of 347,000 recipients targeted for Trezor alone.
This incident highlights a major systemic flaw: the reliance of crypto firms on third-party services. Brevo has confirmed unauthorized access to 138 client accounts, which allowed not only for the mass distribution of malicious messages but also, in some cases, the export of contact databases. For Trezor, this mishap adds to a string of bad luck, following a data breach at their logistics provider, ShipMonk, just weeks earlier, which exposed the contact details of over 80,000 customers. While the hardware security of the wallets themselves remains intact, the recurring nature of these partner breaches severely undermines user trust.
The implications of this case extend well beyond these specific companies, underscoring the critical importance of the digital supply chain. While physical wallets ensure impenetrable protection for private keys, the "weak link" is now shifting toward third-party management services, which are often less secure yet central to customer relations. This new reality demands heightened vigilance, serving as a reminder to investors that no communication, even when received through an official channel, should ever justify the disclosure of their secret phrase.