Roughly 347,000 Trezor newsletter subscribers received an email on September 9, 2026, warning of a critical hardware vulnerability. It looked official. It came from Trezor’s own mailing infrastructure. It was a scam, sent by attackers who never touched a single Trezor device.
That gap between “device secure” and “you’re still at risk” is exactly what makes this incident worth understanding. Even password vaults have fallen to third-party platform exploits, underscoring how no ecosystem is fully insulated from vendor-side risk.
How Attackers Used Trezor’s Own Newsletter Against Its Customers
A flaw in Brevo’s access controls handed attackers the keys to over a hundred client accounts at once.
Brevo, the email marketing…







