YFarmX logoYFarmX

Crypto NewsSecurity

Trezor phishing alert passed email checks as YFarmX examines the takedown

Brevo confirms access to 120 accounts, closed at 09:30 UTC on 10 September. YFarmX’s later checks found the shared public DKIM key still published.

Editorial illustration of a fishing hook through a Trezor-themed email, beside a hardware wallet and Brevo wordmark.

A fraudulent security alert reached Trezor customers on 9 September through the company’s own newsletter platform. Brevo has since confirmed that an attacker accessed 120 accounts and says it closed that access at 09:30 UTC on 10 September. YFarmX’s later DNS checks found the shared public DKIM key still published.

Late on 9 September, Trezor owners began receiving an email titled “Critical Security Alert: STM32 Entropy Vulnerability”, from Trezor Security [email protected]. It passed SPF, DKIM and DMARC (the three checks that separate genuine mail from forgery) because in the only sense a spam filter understands, it was genuine: it went out through Trezor’s own account on Brevo, the marketing platform behind its authenticated mailing.trezor.io domain.

Within the hour, Trezor confirmed on X that its “third-party e-mail provider has been breached”, said the domain had been taken down, and told users to click nothing.

The email claims a factory defect in the STM32 microcontroller inside Trezor devices leaves roughly one in four generating weak, 40-bit seeds, and offers a “check if you’re affected” link, routed through r.mailing.trezor.io, Brevo’s click-tracker sitting on Trezor’s own subdomain. Real sender, real link.

The trap is the next step: “verification” of your xPub, which cannot spend funds but exposes every address and balance you hold, a wealth-ranked target list. Parallel campaigns against other wallet brands then ask for the recovery phrase itself.

Update, 10 September: Brevo confirms 120 affected accounts

In a statement posted by Brevo’s official account, the company said a security incident allowed an attacker to access 120 Brevo accounts. It said most of those accounts showed no suspicious activity, while the attacker used the access to send phishing emails to customer contact lists. The 120 figure describes accounts accessed; Brevo did not say all 120 sent phishing emails.

Brevo said the unauthorised access was closed at 11:30 CEST on 10 September, equivalent to 09:30 UTC. It said it was contacting every affected customer directly and would publish a full post-mortem later that day on its status site. The screenshot supplied for this update records that statement from @brevo_official.

At 14:10 UTC on 10 September, YFarmX’s follow-up DNS check found the same 1024-bit RSA public key still published across all six records below. That check was 4 hours 40 minutes after Brevo’s stated closure time, roughly 17 hours after the phishing campaign the previous evening.

DKIM record checked Finding at 14:10 UTC
mail._domainkey.trezor.io Same public key published
mail._domainkey.mailing.trezor.io Same public key published
mail._domainkey.bitbox.swiss Same public key published
mail._domainkey.shiftcrypto.ch Same public key published
mail._domainkey.brevo.com Same public key published
mail._domainkey.sendinblue.com Same public key published

The mailing.trezor.io SPF record remained absent. Our earlier check had already found no TXT record there at 21:18 UTC on 9 September; the later evidence capture below records the position at 22:06 UTC.

Account access and signing keys are separate controls. Brevo can revoke API credentials or close account access while retaining an existing DKIM key. The DNS checks establish that the public key had not changed at the six sampled records. They establish neither continuing attacker access nor that a private signing key was copied. The six-record sample also does not establish the signing configuration of all 120 affected accounts. Brevo’s post-mortem should clarify how access was obtained and whether signing-key security was affected.

Brevo’s public service-status page still displayed normal operation when checked for this update. That service-status display should be read alongside the company’s separate incident statement on X.

The earlier account investigation reported unauthorised API keys being created and used to send phishing messages. Brevo’s statement now expands the confirmed account-access scope to 120, while leaving the initial route of compromise to the promised post-mortem.

Earlier abuse of authenticated sender accounts

CoinTracking’s November 2025 security notice documents a relevant precedent: an attacker accessed its SendGrid account, uploaded an external contact list and sent phishing through its verified sender domain. Of 127,973 targeted addresses, 96.8% belonged to people outside CoinTracking’s user base. CoinTracking said it reset credentials and secured that account. The case demonstrates how an attacker can use a brand’s authenticated sender identity with a separate recipient list; it does not establish the same actors or list source in this Brevo incident.

What our checks found

At 21:18 UTC on 9 September, YFarmX examined the DNS. The SPF record for mailing.trezor.io was absent, removing that domain’s published SPF authorisation. Aligned DKIM signatures can still satisfy DMARC independently of SPF. At that check, the tracking hostname resolved to Cloudflare edge addresses, but the tested HTTPS connection failed before a redirect could load.

Rendered DNS and TLS probes for the Trezor mailing redirector, alongside a successful trezor.io control request.
Redirector checks at 22:06 UTC on 9 September 2026. Rendered command output supplied for this report, showing DNS resolution and a failed TLS handshake alongside the trezor.io control request. Open full-size capture.

What remains is more interesting. Both DKIM signing keys (mail._domainkey.trezor.io and its twin on the mailing subdomain) were still published at 21:20 UTC: the exact 1024-bit RSA key, half the length of current best practice, that authenticated the phish.

DMARC can pass on an aligned DKIM signature alone. At the 9 September checks, provider-side access revocation was still unconfirmed. Brevo’s subsequent statement dates closure to 09:30 UTC on 10 September; the later DNS findings and their limits are set out above.

Rendered DNS command output showing the absent mailing-domain TXT record, retained MX and DKIM records, and Brevo verification record.
DNS records at 22:06 UTC on 9 September 2026. Rendered command output supplied for this report; the capture shows the mailing-domain TXT lookup, retained MX and DKIM records, and the Brevo verification record. Open full-size capture.

A follow-up DNS check at 22:26 UTC found the same 1024-bit RSA public key published under the mail DKIM selector for trezor.io, bitbox.swiss and shiftcrypto.ch. The saved DNS responses and matching key fingerprints document a shared signing configuration across the three domains. This supports the Brevo infrastructure connection identified in YFarmX’s research.

BitBox’s own statement says its preliminary investigation points to a likely newsletter-provider compromise and that several targeted Bitcoin companies appear to share that provider. The DNS match identifies shared public-key configuration; the provider’s investigation will establish the route of access.

We also decoded something hiding in the campaign’s earlier wave. Subject lines reported by users on Trezor’s forum in August render as “Firmware Vulnerability Notice”, but the text contains U+E0106, an invisible Unicode “variation selector”, inserted inside “Firmware”, “Vulnerability” and “Notice”. Filters scanning for those trigger words never match them; readers see nothing at all.

Rendered Unicode decode identifying three U+E0106 variation selectors in the earlier phishing subject line.
Unicode decode captured at 22:06 UTC on 9 September 2026. Rendered command output supplied for this report, using the earlier August forum title and its URL slug. Open full-size capture.

The wider swarm is visible in public scanning data: urlscan.io logged 504 Trezor-themed pages in 72 hours, including five fresh fakes spun up on Cloudflare Pages in the hour around Trezor’s warning. One older capture supplies the punchline: in August 2025, this same Brevo account was sending Trezor mail tagged utm_campaign=Phishing_Protection.

Rendered urlscan search output with 507 Trezor-themed results and twelve recent entries.
The later urlscan snapshot records 507 Trezor-themed results at 22:06 UTC on 9 September 2026, following the earlier count of 504 cited above. Rendered command output supplied for this report; search matches provide wider context and do not establish that every result belongs to this email campaign. Open full-size capture.

A true story with the logo swapped

The lure works because every ingredient is individually true. In March 2021, rival wallet Coldcard shipped firmware in which one misread compiler flag silently swapped the STM32 chip’s hardware random-number generator for a weak software fallback, collapsing seed entropy to roughly 40 bits.

From 30 July this year, attackers swept the resulting wallets: $70m in 41 minutes in the first wave, around 1,816 BTC (some $116m) in total, with at least fifteen separate attackers piling in.

For six weeks, “check whether your seed is weak” has been legitimate industry advice. The phish simply wears it, and Trezor devices really do use STM32 chips. The claimed defect just isn’t theirs.

Where did the mailing list come from?

The documented trail runs through ShinyHunters, the extortion crew that exploited CVE-2026-72898, a maximum-severity SQL injection in the Metabase analytics platform, to raid Trezor’s fulfilment partner ShipMonk. That breach exposed 80,689 customers’ names, home addresses, phone numbers and emails, including 67,000 records from 2019–21 orders ShipMonk had confirmed in writing were deleted.

Whether the same crew took the Brevo account, or sold access on, is the question Trezor is now investigating; nobody has claimed it.

Nor is it the first time. The same Sendinblue/Brevo account sent an unauthorised “Assets undergoing upgrade” email in January 2024. Mailchimp, Trezor’s previous newsletter provider, was compromised in 2022 by an insider targeting crypto companies. Its support platform was abused in 2025 to send phishing from [email protected].

Since August, exposed customers have reported scam calls and forged letters carrying QR codes. The devices have never been the way in. The marketing stack is.

The defence is unchanged and absolute: no genuine message from any wallet maker asks for a recovery phrase or an xPub, and a backup is entered nowhere except on the device itself. Any emailed “check if you’re affected” tool is the attack.

Sources

  1. Brevo: official account statement, 10 September 2026 (screenshot supplied to YFarmX)x.com
  2. Brevo: public service statusstatus.brevo.com
  3. TRM Labs: Coldcard exploit analysistrmlabs.com
  4. Trezor: official warningx.com
  5. BitBox: newsletter-provider investigationx.com

How we use AI