Trezor phishing alert passed email checks as YFarmX examines the takedown
Brevo confirms access to 120 accounts, closed at 09:30 UTC on 10 September. YFarmX’s later checks found the shared public DKIM key still published.

A fraudulent security alert reached Trezor customers on 9 September through the company’s own newsletter platform. Brevo has since confirmed that an attacker accessed 120 accounts and says it closed that access at 09:30 UTC on 10 September. YFarmX’s later DNS checks found the shared public DKIM key still published.
Late on 9 September, Trezor owners began receiving an email titled “Critical Security Alert: STM32 Entropy Vulnerability”, from Trezor Security [email protected]. It passed SPF, DKIM and DMARC (the three checks that separate genuine mail from forgery) because in the only sense a spam filter understands, it was genuine: it went out through Trezor’s own account on Brevo, the marketing platform behind its authenticated mailing.trezor.io domain.
Within the hour, Trezor confirmed on X that its “third-party e-mail provider has been breached”, said the domain had been taken down, and told users to click nothing.
The email claims a factory defect in the STM32 microcontroller inside Trezor devices leaves roughly one in four generating weak, 40-bit seeds, and offers a “check if you’re affected” link, routed through r.mailing.trezor.io, Brevo’s click-tracker sitting on Trezor’s own subdomain. Real sender, real link.
The trap is the next step: “verification” of your xPub, which cannot spend funds but exposes every address and balance you hold, a wealth-ranked target list. Parallel campaigns against other wallet brands then ask for the recovery phrase itself.
Update, 10 September: Brevo confirms 120 affected accounts
In a statement posted by Brevo’s official account, the company said a security incident allowed an attacker to access 120 Brevo accounts. It said most of those accounts showed no suspicious activity, while the attacker used the access to send phishing emails to customer contact lists. The 120 figure describes accounts accessed; Brevo did not say all 120 sent phishing emails.
Brevo said the unauthorised access was closed at 11:30 CEST on 10 September, equivalent to 09:30 UTC. It said it was contacting every affected customer directly and would publish a full post-mortem later that day on its status site. The screenshot supplied for this update records that statement from @brevo_official.
At 14:10 UTC on 10 September, YFarmX’s follow-up DNS check found the same 1024-bit RSA public key still published across all six records below. That check was 4 hours 40 minutes after Brevo’s stated closure time, roughly 17 hours after the phishing campaign the previous evening.
| DKIM record checked | Finding at 14:10 UTC |
|---|---|
mail._domainkey.trezor.io |
Same public key published |
mail._domainkey.mailing.trezor.io |
Same public key published |
mail._domainkey.bitbox.swiss |
Same public key published |
mail._domainkey.shiftcrypto.ch |
Same public key published |
mail._domainkey.brevo.com |
Same public key published |
mail._domainkey.sendinblue.com |
Same public key published |
The mailing.trezor.io SPF record remained absent. Our earlier check had already found no TXT record there at 21:18 UTC on 9 September; the later evidence capture below records the position at 22:06 UTC.
Account access and signing keys are separate controls. Brevo can revoke API credentials or close account access while retaining an existing DKIM key. The DNS checks establish that the public key had not changed at the six sampled records. They establish neither continuing attacker access nor that a private signing key was copied. The six-record sample also does not establish the signing configuration of all 120 affected accounts. Brevo’s post-mortem should clarify how access was obtained and whether signing-key security was affected.
Brevo’s public service-status page still displayed normal operation when checked for this update. That service-status display should be read alongside the company’s separate incident statement on X.
The earlier account investigation reported unauthorised API keys being created and used to send phishing messages. Brevo’s statement now expands the confirmed account-access scope to 120, while leaving the initial route of compromise to the promised post-mortem.
Earlier abuse of authenticated sender accounts
CoinTracking’s November 2025 security notice documents a relevant precedent: an attacker accessed its SendGrid account, uploaded an external contact list and sent phishing through its verified sender domain. Of 127,973 targeted addresses, 96.8% belonged to people outside CoinTracking’s user base. CoinTracking said it reset credentials and secured that account. The case demonstrates how an attacker can use a brand’s authenticated sender identity with a separate recipient list; it does not establish the same actors or list source in this Brevo incident.
What our checks found
At 21:18 UTC on 9 September, YFarmX examined the DNS. The SPF record for mailing.trezor.io was absent, removing that domain’s published SPF authorisation. Aligned DKIM signatures can still satisfy DMARC independently of SPF. At that check, the tracking hostname resolved to Cloudflare edge addresses, but the tested HTTPS connection failed before a redirect could load.
What remains is more interesting. Both DKIM signing keys (mail._domainkey.trezor.io and its twin on the mailing subdomain) were still published at 21:20 UTC: the exact 1024-bit RSA key, half the length of current best practice, that authenticated the phish.
DMARC can pass on an aligned DKIM signature alone. At the 9 September checks, provider-side access revocation was still unconfirmed. Brevo’s subsequent statement dates closure to 09:30 UTC on 10 September; the later DNS findings and their limits are set out above.
A follow-up DNS check at 22:26 UTC found the same 1024-bit RSA public key published under the mail DKIM selector for trezor.io, bitbox.swiss and shiftcrypto.ch. The saved DNS responses and matching key fingerprints document a shared signing configuration across the three domains. This supports the Brevo infrastructure connection identified in YFarmX’s research.
BitBox’s own statement says its preliminary investigation points to a likely newsletter-provider compromise and that several targeted Bitcoin companies appear to share that provider. The DNS match identifies shared public-key configuration; the provider’s investigation will establish the route of access.
We also decoded something hiding in the campaign’s earlier wave. Subject lines reported by users on Trezor’s forum in August render as “Firmware Vulnerability Notice”, but the text contains U+E0106, an invisible Unicode “variation selector”, inserted inside “Firmware”, “Vulnerability” and “Notice”. Filters scanning for those trigger words never match them; readers see nothing at all.
The wider swarm is visible in public scanning data: urlscan.io logged 504 Trezor-themed pages in 72 hours, including five fresh fakes spun up on Cloudflare Pages in the hour around Trezor’s warning. One older capture supplies the punchline: in August 2025, this same Brevo account was sending Trezor mail tagged utm_campaign=Phishing_Protection.
A true story with the logo swapped
The lure works because every ingredient is individually true. In March 2021, rival wallet Coldcard shipped firmware in which one misread compiler flag silently swapped the STM32 chip’s hardware random-number generator for a weak software fallback, collapsing seed entropy to roughly 40 bits.
From 30 July this year, attackers swept the resulting wallets: $70m in 41 minutes in the first wave, around 1,816 BTC (some $116m) in total, with at least fifteen separate attackers piling in.
For six weeks, “check whether your seed is weak” has been legitimate industry advice. The phish simply wears it, and Trezor devices really do use STM32 chips. The claimed defect just isn’t theirs.
Where did the mailing list come from?
The documented trail runs through ShinyHunters, the extortion crew that exploited CVE-2026-72898, a maximum-severity SQL injection in the Metabase analytics platform, to raid Trezor’s fulfilment partner ShipMonk. That breach exposed 80,689 customers’ names, home addresses, phone numbers and emails, including 67,000 records from 2019–21 orders ShipMonk had confirmed in writing were deleted.
Whether the same crew took the Brevo account, or sold access on, is the question Trezor is now investigating; nobody has claimed it.
Nor is it the first time. The same Sendinblue/Brevo account sent an unauthorised “Assets undergoing upgrade” email in January 2024. Mailchimp, Trezor’s previous newsletter provider, was compromised in 2022 by an insider targeting crypto companies. Its support platform was abused in 2025 to send phishing from [email protected].
Since August, exposed customers have reported scam calls and forged letters carrying QR codes. The devices have never been the way in. The marketing stack is.
The defence is unchanged and absolute: no genuine message from any wallet maker asks for a recovery phrase or an xPub, and a backup is entered nowhere except on the device itself. Any emailed “check if you’re affected” tool is the attack.


