Trezor phishing alert passed email checks as YFarmX examines the takedown
A fake Trezor security alert passed SPF, DKIM and DMARC. YFarmX examines the takedown, phishing tactics and customer-data trail.

A fraudulent security alert reached Trezor customers on 9 September through the company’s own newsletter platform. YFarmX ran its own checks on the wreckage, and found the takedown only half-finished.
Late on 9 September, Trezor owners began receiving an email titled “Critical Security Alert: STM32 Entropy Vulnerability”, from Trezor Security [email protected]. It passed SPF, DKIM and DMARC (the three checks that separate genuine mail from forgery) because in the only sense a spam filter understands, it was genuine: it went out through Trezor’s own account on Brevo, the marketing platform behind its authenticated mailing.trezor.io domain.
Within the hour, Trezor confirmed on X that its “third-party e-mail provider has been breached”, said the domain had been taken down, and told users to click nothing.
The email claims a factory defect in the STM32 microcontroller inside Trezor devices leaves roughly one in four generating weak, 40-bit seeds, and offers a “check if you’re affected” link, routed through r.mailing.trezor.io, Brevo’s click-tracker sitting on Trezor’s own subdomain. Real sender, real link.
The trap is the next step: “verification” of your xPub, which cannot spend funds but exposes every address and balance you hold, a wealth-ranked target list. Parallel campaigns against other wallet brands then ask for the recovery phrase itself.
What our checks found
At 21:18 UTC, YFarmX examined the DNS. The takedown is real but half-finished. The SPF record for mailing.trezor.io is gone, breaking authentication for further sends from that domain. The tracking subdomain still resolves to Cloudflare edge addresses, but HTTPS handshakes are now fatally rejected, so every link in the email dies with a browser security error instead of redirecting.
What remains is more interesting. Both DKIM signing keys (mail._domainkey.trezor.io and its twin on the mailing subdomain) were still published at 21:20 UTC: the exact 1024-bit RSA key, half the length of current best practice, that authenticated the phish.
DMARC passes on an aligned DKIM signature alone. Until those keys rotate and provider-side access is confirmed closed, deleting SPF does not fully shut the door.
A follow-up DNS check at 22:26 UTC found the same 1024-bit RSA public key published under the mail DKIM selector for trezor.io, bitbox.swiss and shiftcrypto.ch. The saved DNS responses and matching key fingerprints document a shared signing configuration across the three domains. This supports the Brevo infrastructure connection identified in YFarmX’s research.
BitBox’s own statement says its preliminary investigation points to a likely newsletter-provider compromise and that several targeted Bitcoin companies appear to share that provider. The DNS match identifies shared public-key configuration; the provider’s investigation will establish the route of access.
We also decoded something hiding in the campaign’s earlier wave. Subject lines reported by users on Trezor’s forum in August render as “Firmware Vulnerability Notice”, but the text contains U+E0106, an invisible Unicode “variation selector”, inserted inside “Firmware”, “Vulnerability” and “Notice”. Filters scanning for those trigger words never match them; readers see nothing at all.
The wider swarm is visible in public scanning data: urlscan.io logged 504 Trezor-themed pages in 72 hours, including five fresh fakes spun up on Cloudflare Pages in the hour around Trezor’s warning. One older capture supplies the punchline: in August 2025, this same Brevo account was sending Trezor mail tagged utm_campaign=Phishing_Protection.
A true story with the logo swapped
The lure works because every ingredient is individually true. In March 2021, rival wallet Coldcard shipped firmware in which one misread compiler flag silently swapped the STM32 chip’s hardware random-number generator for a weak software fallback, collapsing seed entropy to roughly 40 bits.
From 30 July this year, attackers swept the resulting wallets: $70m in 41 minutes in the first wave, around 1,816 BTC (some $116m) in total, with at least fifteen separate attackers piling in.
For six weeks, “check whether your seed is weak” has been legitimate industry advice. The phish simply wears it, and Trezor devices really do use STM32 chips. The claimed defect just isn’t theirs.
Where did the mailing list come from?
The documented trail runs through ShinyHunters, the extortion crew that exploited CVE-2026-72898, a maximum-severity SQL injection in the Metabase analytics platform, to raid Trezor’s fulfilment partner ShipMonk. That breach exposed 80,689 customers’ names, home addresses, phone numbers and emails, including 67,000 records from 2019–21 orders ShipMonk had confirmed in writing were deleted.
Whether the same crew took the Brevo account, or sold access on, is the question Trezor is now investigating; nobody has claimed it.
Nor is it the first time. The same Sendinblue/Brevo account sent an unauthorised “Assets undergoing upgrade” email in January 2024. Mailchimp, Trezor’s previous newsletter provider, was compromised in 2022 by an insider targeting crypto companies. Its support platform was abused in 2025 to send phishing from [email protected].
Since August, exposed customers have reported scam calls and forged letters carrying QR codes. The devices have never been the way in. The marketing stack is.
The defence is unchanged and absolute: no genuine message from any wallet maker asks for a recovery phrase or an xPub, and a backup is entered nowhere except on the device itself. Any emailed “check if you’re affected” tool is the attack.


