Skip to content

347,000 fake messages to crypto wallet owners: the breach hit the firm that sends their newsletters, not the wallet itself

1 min read
Share
347,000 fake messages to crypto wallet owners: the breach hit the firm that sends their newsletters, not the wallet itself

Hardware crypto wallet maker Trezor is warning its customers for the second time in two months that a company it depends on has been hacked. Not the wallet itself - that is untouched. The firms around it.

This time the target was Brevo, the marketing platform Trezor uses to send newsletters. The attackers managed to send around 347,000 phishing messages to Trezor customers, with a malicious link that appeared to come from the company itself. The link downloads an application that asks the victim for their wallet backup password. One of the subject lines read: "Critical security alert: STM32 entropy vulnerability" - wording technical enough to sound genuine, which is the point.

With a stolen wallet password, an attacker takes the funds on the public blockchain. Irreversibly. There is no bank to reverse the transaction, no complaints line, no waiting for a resolution. This is the part the crypto industry sold as an advantage while prices were rising - now that same property is what makes the scam profitable.

In its statement on the incident, Brevo explained that the hackers accessed 138 accounts and sent that entire volume of messages from them. The cause: a flaw meaning access was not "properly restricted" - the hackers gained reach into every organisation their accounts could touch. In other words, one hole in one marketing tool opened a door to hundreds of thousands of crypto owners.

This is Trezor's second breach in a short span. In August the company informed customers that its fulfilment provider ShipMonk had been hacked, exposing the names, phone numbers, email addresses and postal addresses of at least 81,000 people who had bought its hardware. And that is the more dangerous of the two. A list with a name, an address and confirmation that the person owns a crypto wallet is exactly what is needed by those who do not do phishing but turn up at the door. In the weeks after that breach, some people received letters in the post supposedly from Trezor, with a QR code leading to a fake password page.

Trezor says it is reviewing its relationships with its suppliers and has warned customers their addresses could be used again. That is honest, but it is also an admission that a device's security is only as strong as the weakest part of the chain around it. You buy hardware precisely so you do not have to trust anybody - and then your data passes through a newsletter company and a shipping company, and gets sold off there.