This is the second data breach affecting a company that hardware crypto wallet maker Trezor relies on.
By Nexvoro Tech Wire
PUBLISHED FRI, SEP 11, 2026 1:59 PM UTC • 6 MIN READ
Primary Journalistic Dispatch & Direct Reporting
Disrupt 2026: OpenAI, Anthropic, Replit, and more take over 6 industry stages. 25% off tickets now
Hardware crypto wallet maker Trezor is warning customers for the second time in as many months that one of the companies it relies on was hacked, exposing the data of Trezor's customers to hackers.
The link, when tapped, downloads an app that asks the victim for their wallet backup password. According to Trezor, one of the email subject lines said: "Critical Security Alert: STM32 Entropy Vulnerability."
In-Depth Developments & Factual Context
With a stolen wallet password, a hacker can irreversibly steal the person's funds on the public blockchain.
Brevo said in an incident status post that the hackers were able to access 138 Brevo accounts to send out the mass volume of phishing messages. Brevo said that the hackers abused a flaw that meant the hackers' access was "not properly scoped." The company said that the hackers' access was "wrongly granted" to all organizations that the hackers' accounts could reach.
The breach highlights a common security incident, where hackers compromise data held by third-party companies that are necessary for fulfilling orders or purchases from customers. Trezor says none of its products, wallets, or account system was affected by the incident.
Industry Impact & Strategic Analysis
This is the second breach in recent weeks affecting Trezor, after the company alerted customers in August that one of its shipping partners was compromised in a data breach . The incident at the mailing company ShipMonk exposed the names, phone numbers, email addresses, and postal addresses of at least 81,000 people who bought and received Trezor wallet hardware.
The data breach could put crypto owners and other wealthy individuals at risk of targeted violence and so-called "wrench" attacks , which rely on physical attacks to extract passwords from people.
In the weeks following the breach at ShipMonk, some people have received letters by mail claiming to be from Trezor, featuring a QR code that, when scanned, opens up a fake page that attempts to steal the victim's crypto wallet password.
Forward Outlook & Market Perspective
Trezor said it was reevaluating its relationships with its vendors and warned customers that their email addresses may be used again for future phishing attacks.
When you purchase through links in our articles, we may earn a small commission . This doesn't affect our editorial independence.
He can be reached via encrypted message at zackwhittaker.1337 on Signal. You can also contact him by email, or to verify outreach, at zack.whittaker@techcrunch.com .
Don't miss out . The startup community will gather to answer a pivotal question: How do you build sustainably in the AI era?
ID verification giant IDScan confirms data breach with more than 150 million driver's licenses stolen
Automattic's board forces CEO Matt Mullenweg into leave of absence
Reporting synthesized and verified under Nexvoro.tech editorial guidelines. Full primary records referenced via TechCrunch.
Reporting synthesized under Nexvoro.tech Editorial Standards • Referenced via TechCrunch
Verified Dispatch