Trezor Email Provider Breach (Brevo, September 2026)
Auto-generated score, not yet verified against the scoring model. Under review — treat as indicative, not a verdict.
anchored·5FUUAD…76nTSummary
On September 9, 2026, attackers exploited a SAML SSO misconfiguration at Brevo, Trezor's third-party email marketing provider, to access 138 Brevo customer accounts and send phishing emails to approximately 347,000 Trezor newsletter subscribers. The messages falsely claimed a critical STM32 microcontroller entropy vulnerability required users to re-enter their seed phrases; approximately 2,500 users clicked the malicious link before Trezor disabled the phishing domain within 20 minutes. No cryptocurrency losses have been confirmed as of mid-September 2026, but the incident forms part of a pattern of third-party supply-chain attacks targeting Trezor users across multiple vendor relationships.
Connected Entities
4 entities · 60 linked investigations- Trezor Email Provider Breach (Brevo, September 2026)→mentioned with→ShipMonk(70%)
- Trezor Email Provider Breach (Brevo, September 2026)→mentioned with→Solana(70%)
- Trezor Email Provider Breach (Brevo, September 2026)→mentioned with→Trezor(70%)
- Trezor→mentioned with→Solana(75%)
- ShipMonk→mentioned with→Trezor(80%)
Connected Through
3 shared actors · 404 investigationsDistinct actors this investigation shares with others — holders, traders, and named parties. Shared infrastructure (exchanges, pools) is excluded.
- □Solanaorganizationalso inKelpDAO / LayerZero Bridge Exploit (April 2026) — DPRK Lazarus·0Q2 2026 Bridge Exploit Wave·0CATFI Memecoin·0BonkDAO Treasury Governance Attack·0Q2 2026 Record Crypto Hack Wave·0Ben Pasternak / Believe / LAUNCHCOIN·0MEV Bot Scam — YouTube AI Trading Bot Campaign (2026)·0Mach-O Man Malware Campaign (Lazarus / Chollima)·0DPRK IT Worker Network (Overseas Scheme)·0Yelo (yelotree)·0Lab·0Solana Blinks / Durable-Nonce Drainer Kits (2026)·0H1 2026 Bridge Hack Cluster — Same-Day $35.6M Attack Wave July 22-23·0Google Coin / Fake Gemini AI Chatbot Presale Operation·0Solana Token-2022 Permanent Delegate Rug Pull Factory·0AI Agent Prompt Injection Crypto Attack Class (2026)·0fake Ledger Live app·0Sam Bankman-Fried·0LAB / LABUSDT·0H2 2026 July Bridge Hack Wave — Seven Attacks, $M+ Lost·0BonkDAO Treasury Governance Attack (July 2026)·0DeFi Governance Attack Wave 2026·0Drift Protocol DPRK Exploit (April 2026)·0Hayden Davis·0HAWK·0Fake Crypto AML Checker Infrastructure·0World Cup 2026 — Stake.com Impersonation Wallet Drainer Campaign·0CATFI Memecoin / Eth Father (Park)·0Fake Jupiter CJUP Airdrop Phishing Campaign·0LAB Token (LabsAI)·0Fake Uniswap V4 Airdrop Phishing Network (2026)·0Adam22 (Adam John Grandmaison) — $CUCK Meme Coin·0Q2 2026 DeFi Record Hack Wave·0Iranian Crypto Exchanges OFAC Designation — Nobitex, Wallex, Bitpin, Ramzinex (June 2026)·0DPRK Lazarus April 2026 $635M Blitz — Drift + Kelp Combined Campaign·0Iggy Azalea / MOTHER Memecoin·0Citrine Sleet / AppleJeus·0Solana MEV Sandwich Bots·0Broox Bauer / Axiom Insider Trading Ring·0requests-secure-v2·0Mass Address Poisoning Campaign (Ethereum 2025-2026)·0npm debug / chalk Supply Chain Attack (September 2025)·0Ill Bloom Vulnerability·0AscendEX (BitMax)·0AI Hallucinations·0Rugproof (Solana Launchpad)·0ChainDrop / Mini Shai-Hulud npm Supply Chain Worm (August 2026)·0CrediX Protocol Exit Scam·0North Korea Lazarus Group — H1 2026 Systematic Crypto Theft Campaign·0GSD Cloud / Lex Christopherson·0Sector Drainer — DaaS Wallet Drainer with Phantom 0-Day Bypass·0Rust Crypto Clipper Malware — Fake GitHub Stars Campaign·0Pump.fun·0CarbonVote Token·0DSJEX / BG Wealth Sharing Ponzi·0Shai-Hulud / TeamPCP Supply Chain Attack·0H1 2026 Crypto Hack Landscape — AI Agent Attack Vector Emerges·0Quark Drainer·0Holoworld AI — AVA Token Insider Bundling Scheme·0Rug Republic — Coordinated Pump.fun / Solana Bundle-Rug Cluster·0John Daghita (aka Lick) — US Marshals Crypto Theft·0TeamPCP / Mini Shai-Hulud npm Supply Chain Worm·0DPRK Crypto Theft H1 2026 (TRM Labs / Blockaid Report)·0Apple App Store — Systematic Fake Crypto Wallet Cluster (26 Apps, April 2026)·0Alex Larson Schultz / OverHere Limited (HAWK Memecoin)·0CYBERLEEK Token·0Genesis Global Capital·0HECO Bridge & HTX Exchange Hack·1FaZe Banks (Ricky Bengtson) / MLG Coin·1Socket Security Malicious Browser Extension Campaign August 2026·2Google Coin / Fake Gemini AI Chatbot Presale Scam·2Basis Markets·2HQI Exchange·2Robinhood Chain Scam Ecosystem·2Aqua·2Bitforex·2Wiz Khalifa Pump Fun·2Iran War Panic Crypto Scam Network (ORAMAMA / X Account Manipulation)·2Squid Games (SQUID Token)·2OpenClaw GitHub Phishing Campaign·2CatFi Memecoin (CATFI)·2Baller Ape Club·2Trump Digital Gold (GOLD)·2Transit Finance·2CLAWD Token (Fake ClawdBot AI Scam)·2Leva Heal Limited (Fake Ledger Live App - Apple App Store)·2Luna Yield·2MangoFarmSOL·2Magnate Finance·2LIBRA Token·2RiskOnBlast·2Eric Trump Fake Token·2Avraham Eisenberg·2Glori Finance·2Sapphire Sleet / UNC1069·2NFTMachine·2ORAMAMA X War-Panic Scam Network·2Kokomo Finance·2Aquabot (AQUA)·2Rublevka Team·2Fake GTA 6 Leak Wallet-Drainer Campaign·2Dragoma·3AudiA6 Mixing Service·3ORAMAMA Token ($ORAMAMA)·3Sahil Arora·3ZKasino·3FQ1tyso61AH1tzodyJfSwmzsD3GToybbRNoZxUBz21p8·3Kylie Jenner X account hack / $KYLIE Solana memecoin scam·3SIGMA Bot·4LAB Token (Smartliquid AI)·4Crypto Beast (ALT Token Influencer)·4YZY Money·4LAB Token·4CrediX Finance·4LAB Token (AI Terminal / Vova Sadkov)·4DogWifTools·4$TRUMP Memecoin — August 2026 SEC Investigation Request·4Kelsier Labs·4Beaverd (@beaverd)·4Pump.fun / Solana Memecoin Launchpad Ecosystem Fraud·4Crypto Beast·4Kelsier Ventures·4Undisclosed KOL Promo Network (ZachXBT Exposé, September 2025)·5JELLY·5Input Output Group (IOG) YouTube Channel Hijack – Deepfake Hoskinson Giveaway Scam·5Cashio·5Nobitex·5Nirvana V1·5Allbridge Core Second Flash-Loan Exploit (July 2026)·6TartSwap (TART, Solana mint 6MXygsP9QDJiEqGCuHjbsru6vU1YmtynDWnTsx6uWbTv)·7Axiom DEX Insider Trading (Broox Bauer)·8OverHere Limited / Clinton So·8Allbridge Core — Second Flash Loan Exploit via Same Unpatched Vector·8James Wynn·8$TRUMP Memecoin — Presidential Conflict of Interest and Retail Losses·8pump.fun·8Trove Markets·8Allbridge Core — CCTP Base Chain Exploit (August 2026)·8Rhea Finance Exploit (April 2026)·9Nobitex June 2025 Hack (Predatory Sparrow)·10Step Finance Treasury Theft (January 2026)·10DEXX·10Phemex·10Odin.fun·10Bidao·12Meteora / Benjamin Chow·12DeepSnitch AI·12ZachXBT Crypto Influencer Paid-Promotion Leak (200+ Influencers, September 2025)·12Solareum·12MELANIA Memecoin·12Eric Adams / NYC Token·12Waygu / Wagyu·12Undisclosed KOL Paid-Promotion Network (2025)·12Mango Markets·12Step Finance Hack and Shutdown·12ElementalDeFi·12Baton Corporation Ltd (Pump.fun)·12Cypher Protocol·12Allbridge Core Solana Flash Loan Exploit (July 2026)·14Garden Finance·14Arthur Hayes — Maelstrom CIO Exit Liquidity Allegations·14OpenZeppelin AI Exploit Threat Vector·15Remora Markets·16Pump.fun / Solana Labs RICO Class Action·17Pond0x·18FOMO Token·18Cascade Protocol·18Tectonic Protocol·18OlympusDAO·18Noones·18Transit Swap·18WAYGU CASH·18Axiom DEX·18Broox Bauer·18Meteora / M3M3 Token·18Stabble·18Meteora DEX·18Wasabi Protocol·18Believe·18TRUMP Official Memecoin ($TRUMP)·18Baton Corporation (Pump.fun)·18LetsBonk.fun·20Rhea Lend·20Pump.fun / Solana Labs / Jito Labs — RICO MEV Class Action (SDNY 2026)·20Triple-A Treasury Hack (July 2026)·22Hunter Biden ($LAPTOP token)·22Eclipse·22Ratio Finance·22CyberLeek Solana Token·22CyberLeek / CYBERLEEK Solana Token·22Axiom DEX Employee Insider Trading·22ChainSwap·22Fartcoin·22Ranger Finance·22Smoking·22Odin.Fun·22Predatory Sparrow (Gonjeshke Darande)·22Roman Storm·22Aster (ASTER)·23Metawin·23Goatseus Maximus (GOAT)·23Carrot Protocol·24y00ts·24BigONE Exchange·24Aurory·26Frank DeGods·26BullX·27Shibarium·28Boop (boop.fun)·28DeFiTuna·28ElizaOS / AI16Z (Eliza Labs)·28Aquifer AMM·28Moola Market·28GemPad·28Allbridge·28Texture Finance·28Meteora·28Nirvana Finance·28ACT·28Axiom Trading·28Omm·28Trust Wallet Chrome Extension Hack (December 2025)·28StablR — Multisig Exploit and EURR/USDR Depeg·28Crema Finance·28Bridgers Cross-Chain Swap·28Slope Wallet·28Dunamu / Upbit·30Axiom Exchange — Employee Insider Trading Scandal·30BonkDAO·30Across Protocol Solana Bridge Exploit (July 2026)·30Shiba Inu (SHIB)·31Cropper Finance·32Daos.fun·32Adrena Protocol·32PiggyBank Protocol·32Axiom·32Zinc·32Eleven Finance·32TeleSwap·32Brevo (email marketing platform used by Trezor, BitBox, CoinTracking, Solana Mobile)·32GoonFi·32Axiom (Solana DEX)·32Saga·32Rhea Finance·32Aldrin·32Banana Gun·32Stonk·32Bonk·33Epicentral Labs·34Honeyland·34Andy Ayrey·34DeGods·34Kiln·355CLYzCRa2E8p3NHNrRSs2w5NkHzj5WGmqCF8zYd3PRD7·35Cod3x·36Genopets·37Griffain·37CoinDCX·38Chads NFT·38Ansem / $ANSEM ("Black Bull") creator-coin controversy·38Fogo·38Avici·38Dogwifhat (WIF)·38IoTeX·38Symbiosis Finance·38Thunder Terminal·38MustStopMurad·38BitoPro·38M2 Exchange·38Polycule·38Triple-A·38Save·38Rain·38Bonad·38Grass·38Loopscale·38M2·39Jump Trading·42Chainflip·42Midnight Network / NIGHT Token·42Brevo·42YO Protocol·42Tria·42Allbridge Core·42GooseFX·42Granary Finance (GRAIN)·42Houdini Swap·42SOL Strategies Inc. (STKE)·42Pudgy Penguins·42Zerion Wallet·43GMGN.ai·43Lifinity·47SwissBorg·47Maestro·47Access Protocol·47Flash Trade·48SKR·48BonkBot·49Aptos·50ZRX (0x Protocol)·50Ottersex·507uh2UVF8hpQjLdUwr7gffJWJfymVcjVLVvC7j9tdCuvD·50Fragmetric·50Ledger Live·50Sky (MakerDAO)·51Teraswitch (Solana validator hosting concentration incident)·52Internet Computer·52Decaf·52Leap Wallet·52Drift Protocol·52Avalanche·52USX·52Fomo (fomo.family)·52Claynosaurz·52Hxro Network·53PayPal USD (PYUSD)·53Robinhood Crypto·54Fuse Wallet·54Jupiter Perps·54HEEBOO·54Polygon·54Lulo·55Exponent Finance·55Render Network·55YLDS·56Global Dollar (USDG)·56DRiP Haus·56Famous Fox Federation·57Trezor·57Audius·58Titan Exchange·58Cega·58Upbit·58Helium (HNT)·58Rain Financial (Crypto Card Infrastructure)·58Helium Mobile·58Backpack·59Ondo US Dollar Yield (USDY)·60Light Protocol·61Solana·62Raydium Protocol·62cat in a dogs world·62Raydium AMM·62Matcha·62Circle Internet Financial·62Jupiter Exchange·62Wormhole·62Porkbun·62Dual Finance·62Jito Labs·62Circle·62Phantom Wallet·63Invesco Short Duration US Government Securities Fund (USTB)·63Firedancer·63Wormhole Bridge·63Madlads·65USDGO·66Helius·67Clockwork·68Hivemapper·68Edgevana·69Anza·69Dialect·69Crossmint·70USD Coin (USDC)·71Glow Wallet·72Superteam·72Bybit·72Cardano·72Phoenix Trade·72Ondo Finance·72Circle USYC·73BlazeStake·73Kamino Finance·74Asymmetric Research·77Marinade Finance·79Orca·80BlackRock USD Institutional Digital Liquidity Fund (BUIDL)·82Solana Summit Toronto·82Janus Henderson Anemoy Treasury Fund (JTRSY)·82
- □Trezororganizationalso in$91M Bitcoin Social Engineering Theft — Hardware Wallet Impersonation (August 2026)·0AI-Powered Crypto Phishing Infrastructure 2026·0Fake Trezor Support Social Engineering — $282M Heist·0IRS Fake Digital Asset Compliance Portal Letter Campaign — 2026·0Tiffany Milanovich·0Patrick Yarmoch (FBI Agent — Crypto Theft)·0Patrick Steven Yaroch — FBI Agent Crypto Theft·0Fake Sparrow Wallet (Apple App Store)·0Coldcard Fake Hardware Audit Phishing Campaign·0Apple App Store — Systematic Fake Crypto Wallet Cluster (26 Apps, April 2026)·0CastleLoader / NeedleStealer Crypto Wallet Malware Campaign·0IRS Fake Digital Asset Compliance Portal — Physical Mail Phishing·0Socket Security Malicious Browser Extension Campaign August 2026·2Trenton Richard Johnston·2Trenton Johnston — Crypto Social Engineering Theft Ring·2Rublevka Team·2Coldcard / Coinkite Firmware Seed-Generation Exploit (July-August 2026)·3CryptoJS Ill Bloom — Weak RNG Multi-Wallet Drain (CVE-2026-71851)·4Brandon Michael Tardibone·4Coldcard / Coinkite Hardware Wallet Firmware Exploit·6Coinkite·15ShipMonk·16Shuffle (shuffle.com)·26Yield Guild Games (YGG)·30Brevo (email marketing platform used by Trezor, BitBox, CoinTracking, Solana Mobile)·32Brevo·42Bits of Gold·44Trezor (ShipMonk Data Breach)·46Trezor·57Electrum·62
- □ShipMonkorganization
Timeline(11 events)
1 April 2022
Mailchimp, a prior Trezor email marketing provider, suffered a social engineering attack that exposed approximately 100 Trezor user accounts and enabled a targeted phishing campaign.
The Register10 August 2026
ShipMonk, Trezor's shipping and logistics vendor, notified Trezor that customer data was exposed via a Metabase SQL injection zero-day (CVE-2026-72898, CVSS 10.0).
Trezor official blog13 August 2026
Trezor publicly disclosed the ShipMonk breach, initially reporting approximately 13,689 affected customers with names, emails, phone numbers, and shipping addresses exposed.
BleepingComputer9 September 2026
Attackers exploited Brevo's SAML SSO misconfiguration, accessed 138 Brevo customer accounts, and sent phishing emails to approximately 347,149 Trezor newsletter subscribers. The emails used the subject line 'Critical Security Alert: STM32 Entropy Vulnerability' and directed recipients to a malicious application requesting seed phrase entry.
Trezor official blog10 September 2026
Brevo detected the SSO access at 6:30 AM UTC and closed the attack vector by 8:30 AM UTC. Trezor disabled the phishing domain within approximately 20 minutes of detection, by which time approximately 2,500 users had clicked the malicious link. Brevo force-signed out all platform users and deployed a permanent SSO scope-restriction fix.
Brevo Status incident write-up11 September 2026
TechCrunch reported that Trezor confirmed the Brevo data breach and described it as the second data breach of a Trezor third-party vendor within weeks.
TechCrunch12 September 2026
Solana Mobile disclosed that its Brevo marketing email account had been accessed without authorization as part of the same Brevo incident and warned users of elevated phishing risk.
CryptoBriefing13 September 2026
Solana Mobile confirmed it had suspended its Brevo marketing email account following unauthorized access.
The Daily Hodl14 September 2026
In a separate secondary attack, attackers used a hardcoded Cloudflare API key to deploy a malicious Cloudflare Worker on Brevo's domains and customer-embedded JavaScript files between approximately 16:05 and 20:13 UTC, injecting ClickFix malware and WordPress backdoor payloads across an estimated 100,000+ customer websites.
SecurityWeek15 September 2026
All malicious subdomains from the September 14 Cloudflare Worker attack stopped resolving. Brevo's JavaScript files were confirmed clean.
BleepingComputer17 September 2026
Trezor updated its disclosure to confirm 347,149 total marketing contacts were affected by the Brevo breach. No confirmed cryptocurrency losses from the phishing campaign were reported as of this date.
Trezor official blogDecision Log
- hash: Hu1G6PDPbKnSvMfrLxyamAmA5G6aYqv2Xqfvdd5ENQKp
This investigation is cryptographically anchored to the Solana blockchain (1 event). 19 of 20 cited source URLs have an Internet Archive snapshot.
model: claude-sonnet-4-6
generated: 9/18/2026, 5:09:04 PM
last updated: 9/18/2026, 8:24:20 PM
avoid.net — verified advice for a post-truth world