Hardware wallet manufacturers Trezor and BitBox are responding to coordinated phishing campaigns that targeted their users following a breach at shared email service provider Brevo. The attacks exploited stolen subscriber data to send fraudulent security alerts about a non-existent STM32 microcontroller vulnerability, attempting to trick users into revealing recovery seeds or installing malicious software.

Trezor confirmed that the incident originated from a breach at its email service provider, stressing that its hardware wallets themselves "remain safe" and were not compromised. The company disclosed that attackers gained access to subscriber information through the third-party platform rather than through any direct breach of Trezor's internal systems. Similarly, BitBox announced it was investigating a likely compromise of its newsletter provider, with indications pointing to the same underlying security incident.

According to Cointelegraph, the phishing campaign reached approximately 347,000 Trezor subscribers. The company stated it is treating every affected email address as "known to the attacker and possibly reusable for phishing," indicating heightened concern about continued targeting of this user base. The phishing emails falsely claimed that STM32 chips used in hardware wallets contained a critical vulnerability requiring immediate firmware updates, a fabrication designed to panic users into taking hasty action.

Bitcoin Magazine reported that this represents another data breach incident for Trezor involving its marketing infrastructure. The publication noted that users of the bitcoin hardware wallet were specifically targeted through compromised access to the marketing platform, rather than through any wallet-specific vulnerability.

The attack methodology reflects a persistent pattern in cryptocurrency security: exploiting trusted communication channels to bypass user skepticism. By using official-looking sender addresses and referencing plausible technical components, the phishing emails attempt to mirror legitimate security communications that hardware wallet users might expect. The STM32 reference is particularly notable because these microcontrollers are genuinely used in many hardware wallets, lending superficial credibility to the fabricated vulnerability claim.

Both manufacturers have urged users to verify any security communications through official channels and to never enter recovery seeds in response to email prompts. Hardware wallets themselves remain secure when used as designed, with the breach limited to email contact information rather than device firmware or private key storage. The incident nonetheless highlights supply chain risks in cryptocurrency infrastructure, where security depends not only on a company's direct controls but on the integrity of service providers handling customer data.

Brevo, formerly known as Sendinblue, has not yet publicly detailed the specific vulnerability that enabled the unauthorized access. The incident adds to growing concerns about marketing platform security in the cryptocurrency sector, where user email lists represent high-value targets due to the financial assets typically associated with such accounts.