Trezor warned customers that attackers who compromised a third-party email provider are sending phishing messages from help@trezor.io. The emails masquerade as urgent security notices and falsely claim an STM32 microcontroller entropy flaw exposes wallet seed phrases to brute-force recovery. Trezor said its own systems were not breached, disabled the phishing domain, and is investigating the provider compromise and the attackers' use of its legitimate email domain; BitBox users were also reportedly targeted through a similar provider-related campaign.
The lure exploits concern over genuine hardware-wallet entropy issues, including a Coldcard Mk3 firmware flaw reportedly linked to theft of roughly 594 BTC from about 500 addresses. Trezor customers also face heightened social-engineering risk after logistics contractor ShipMonk exposed order data for approximately 81,000 customers in a separate breach reportedly tied to a critical Metabase SQL-injection zero-day. Organizations and users should treat unsolicited wallet-security emails as malicious, avoid embedded links, and verify notices through official channels.

Get the infrastructure and lures behind it.
14 events from the most recent confirmed update back to the earliest known activity.
Brevo identified the security issue in its SAML single-sign-on handling. Its postmortem said six compromised customer accounts were used to send phishing emails and contact lists were exported from 43 accounts, potentially enabling further targeted phishing.
Trezor warned customers that attackers who breached its third-party email provider were sending phishing emails from help@trezor.io, falsely alleging an STM32 entropy vulnerability. Trezor disabled the campaign domain, advised users not to follow links, and began investigating the provider breach and access to its legitimate domain.
Trezor disclosed that approximately 67,000 additional U.S. customers were affected by the ShipMonk breach, bringing the total impact to about 81,000 customers. The additional exposed records concerned orders from November 2019 through August 2021 and included names, addresses, phone numbers, and order numbers.
Trezor learned that ShipMonk still retained older customer records despite prior assurances that the data had been deleted.
Trezor disclosed unauthorized access at logistics contractor ShipMonk affecting 13,689 customers. Exposed data included names, postal and delivery addresses, phone numbers, email addresses, cities, and order information; Trezor said its own systems, wallets, private keys, and seed phrases were not compromised.
Metabase said threat actors had exploited a critical SQL-injection zero-day in customer instances, obtaining administrator access and stealing data. Breach notifications indicated this vulnerability was used in the ShipMonk compromise.
Attackers exploited a Coldcard Mk3 firmware build-configuration error that caused use of a software pseudorandom generator, creating vulnerable recovery seed phrases. On July 31, they withdrew approximately 594 BTC, worth about $38 million, from roughly 500 addresses.
BitBox said its hardware wallets were not vulnerable to the entropy issue affecting certain Coldcard devices.
Trezor disclosed that attackers had compromised its third-party support-ticketing portal, exposing names, usernames, and email addresses of roughly 66,000 users.
Brevo said attackers accessed 138 accounts and exploited an authorization-scoping flaw that improperly granted access to all organizations reachable by compromised accounts. The flaw was used to send phishing messages, including those targeting Trezor customers.
Trezor reported that 347,000 customers received Brevo-sent phishing emails impersonating a critical STM32 entropy alert, and approximately 2,500 clicked the malicious link. Trezor took the credential-harvesting site offline 20 minutes after detecting it; any resulting cryptocurrency losses remain unknown.
CoinTracking said its customers received a malicious API-key-reset phishing email and identified Brevo as the compromised email provider. Brevo said an attacker abused 120 customer accounts to send phishing messages to client contact databases and that it had closed the attacker's access.
BitBox issued a similar phishing warning, saying preliminary information indicated its email provider had been compromised and that other Bitcoin companies using the same provider were also affected.
Further affected addresses and stolen funds were identified after the initial Coldcard theft. Coinkite released firmware fixes, although owners of vulnerable seed phrases still needed to generate new phrases and move their funds.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Get the infrastructure, lures, and IOCs behind this campaign, ready to push into your email and identity stack.
7 references tracked. Mallory keeps watching after this page renders.
malwarebytes.com
Open sourcetechcrunch.com
Open sourcesecurityweek.com
Open sourcexakep.ru
Open sourcebleepingcomputer.com
Open sourcetherecord.media
Open sourcetrezor.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.