# The Supply Chain Is the Attack: How Brevo's Breach Put 347,000 Trezor Users in a Phisher's Crosshairs


Hardware wallets are supposed to be the paranoid option. You buy one precisely because you don't trust software, don't trust exchanges, and don't trust that someone else's server is safe enough to hold your life savings in crypto. Then your wallet manufacturer gets you phished anyway — through their email newsletter vendor.


That's what happened to Trezor users after a breach at Brevo, the French email marketing platform formerly known as Sendinblue. An attacker got into Brevo's systems, pulled a database of contacts belonging to Trezor's customer list, and immediately weaponized it: 347,000 users received convincing phishing emails designed to steal their seed phrases — the 12- or 24-word recovery sequences that represent absolute, irrevocable control over a crypto wallet.


## What the Attacker Actually Wanted


Seed phrases are not passwords. You can't reset them. There's no recovery path, no support ticket you can file. If someone has your seed phrase, they own your wallet — permanently, completely, and with no recourse. The phishing campaign's sole purpose was to trick users into typing those words somewhere the attacker controlled.


The emails impersonated Trezor communications. They claimed users needed to take urgent action — upgrade firmware, verify a security setting, confirm identity — and linked to a cloned Trezor interface designed to prompt seed phrase entry. Anyone who complied handed over everything.


Trezor confirmed that a Brevo employee's account was compromised through a targeted social engineering attack against Brevo staff, and that the attacker used that access to export the Trezor subscriber database. Brevo shut down the unauthorized access quickly after detection, but by then the data was already out.


## A Pattern That Keeps Paying Off


This attack is not novel. It is, in fact, distressingly routine — which is the more alarming story here.


In 2020, Ledger (Trezor's main competitor) suffered a breach of its e-commerce database. More than 270,000 customer records — names, email addresses, phone numbers, physical addresses — ended up on hacker forums. What followed was over a year of targeted phishing campaigns, SIM swapping attempts, and in at least some documented cases, threats of physical violence against hardware wallet owners whose home addresses were now public knowledge.


In 2023, Mailchimp — another email marketing platform — was breached twice in the same year, both times through social engineering against internal employees. The attackers specifically sought out crypto-adjacent clients. Web3 company DigitalOcean and several crypto businesses had their subscriber lists extracted and used for phishing.


The pattern is consistent: attackers are not trying to crack the cryptography inside hardware wallets. That's a hard problem. Instead, they're targeting the SaaS layer around the companies that sell those wallets. Email marketing databases are extraordinarily useful because they're lists of known, confirmed crypto holders who have spent money on security-conscious products — self-selected high-value targets.


## Why "Use a Hardware Wallet" Isn't the End of the Conversation


The security community has spent years telling people that hardware wallets are the right answer for serious crypto holders. That advice isn't wrong. But it has a hidden assumption baked in: that the owner understands what the device actually protects them from and what it doesn't.


A hardware wallet keeps your private keys off internet-connected devices. It won't protect your seed phrase if you type it into a phishing site. It won't protect the metadata — your email address, your name, the fact that you hold crypto — that you hand to vendors when you buy the thing. And it won't protect you from a convincing enough email sent from data your wallet company's newsletter provider just leaked.


The threat model for crypto holders has never been purely technical. Social engineering is the attack surface, and it gets more targeted as more data accumulates in more vendor databases.


## HackWire Analysis


Three supply chain attacks in four years, all hitting the same category of victim through the same category of vendor. At some point this stops being a coincidence and starts being a structural problem with how crypto hardware companies handle customer data.


The immediate fix is obvious and worth saying anyway: Trezor should never have stored 347,000 customer email addresses in a third-party marketing platform in a form that made them accessible via a single compromised employee account. The principle of minimum necessary data exposure isn't just a compliance checkbox. In a business where your customers are known to hold significant crypto wealth, your customer list is a target with a dollar sign on it.


But the deeper issue is incentives. Email marketing platforms compete on features and deliverability, not on security. Brevo's breach happened through social engineering of an internal employee — the same attack vector as the Mailchimp breaches. These platforms process enormous volumes of high-value marketing lists with access controls that apparently weren't sufficient to prevent lateral movement from a compromised account.


For defenders: crypto companies should be treating their customer databases like they treat their own wallets — with the assumption that breach is a matter of when, not if. That means data minimization, strict access segmentation, and automatic alerts when bulk exports occur. It means telling customers clearly: we will never email you asking for your seed phrase, and we will never build a web form that asks for it either.


For users: the answer isn't distrust of Trezor specifically. It's a standing policy — no email, no website, no person on the phone ever needs your seed phrase. Ever. If any interface asks for it, that interface is malicious by definition, regardless of how official it looks.


The attackers know exactly who bought hardware wallets. The only remaining question is whether those users know what the hardware actually protects them from.


— HackWire Editorial


---


## Related Coverage


  • Read more in our [Breaches](https://www.hackwire.news/category/breaches) coverage
  • Cross-reference with [Vulnerabilities](https://www.hackwire.news/category/vulnerabilities) and [Malware](https://www.hackwire.news/category/malware)
  • Stay current via the [HackWire homepage](https://www.hackwire.news/)