Trezor breach exposes crypto’s SaaS weak point
A breach at Trezor’s email provider exposed roughly 347,000 newsletter addresses and let attackers send phishing messages from a trusted channel.

Hardware-wallet security can be extremely strong while the software surrounding the customer relationship remains vulnerable.
What happened
A breach at Trezor’s third-party email provider Brevo allowed an attacker to send phishing messages using Trezor’s account. Around 347,000 opt-in newsletter email addresses were affected. Trezor says its own wallet infrastructure was not compromised.
Why it matters
Attackers do not always need to break cryptography. By compromising a trusted communications provider, they can impersonate a wallet company and persuade users to download malicious software or reveal recovery information themselves.
The bigger picture
Crypto security increasingly depends on the entire SaaS supply chain around a wallet provider: email, support systems, analytics and cloud tools. Strong on-device security cannot fully protect users if trusted external channels are compromised.
