Satoshi Gazette
POLICY

The security email was the attack

Attackers used a newsletter provider’s access to send convincing wallet warnings. The failure was outside the hardware wallet—but the message tried to get inside it.

A cream envelope passes beneath glass, casting a hook-shaped shadow toward an intact hardware wallet.
IMAGE: Satoshi Gazette · AI-generated editorial illustration

The email asked readers to protect their bitcoin. Following its instructions was the danger.

Trezor says attackers used its newsletter account to send a false hardware-security warning directing recipients toward an application that requested their wallet backup. Its September 10 disclosure puts the mailing at roughly 347,000 recipients. That is a recipient count, not a count of stolen wallets.

An email carrying Trezor branding and a false hardware-security warning, overlaid with a large red SCAM marking.
Fraudulent email example published by Trezor. The SCAM marking is part of its original image.Source: Trezor, September 10, 2026 · Data as of 2026-09-12Sources: 1
Method

Unchanged source-published example. No visible URL or QR code. Illustrates the deceptive request, not a verified hardware defect.

A familiar sender was not enough

Brevo’s post-mortem describes an access-control failure. An attacker configured single sign-on, invited other users, and obtained access beyond the organization that should have bounded that login.

Brevo says 138 accounts were accessed, with six used for phishing emails and contact exports from 43. Those categories should not be added together: the notice does not establish that they are mutually exclusive. The provider also confirms the messages travelled through legitimate infrastructure and passed ordinary email-authentication checks.

This was not simply an unfamiliar address wearing a familiar logo. The sending system itself had become part of the attack.

Three stages show abused newsletter access, a false warning through legitimate infrastructure, and conditional disclosure of a wallet backup.
A compromised delivery channel is distinct from a compromised hardware wallet. Backup disclosure is conditional.Satoshi Gazette explanatory diagram · Data as of 2026-09-12Sources: 1 · 2
Method

Original SG explanatory schematic from cited statements. Not a complete exploit reconstruction or a measurement of wallet losses.

Different requests, the same borrowed trust

CoinTracking’s warning describes a different lure: an urgent request to refresh API keys. The company says the incident was confined to its external email service, which held neither those keys nor customer portfolio data. The fraudulent message tried to persuade recipients to supply information the attacker did not already possess.

For Trezor users, the requested secret was a wallet backup. Trezor says its products and account systems were not compromised, and its notice does not establish that its newsletter list was exported. Those limits matter. A compromised mailing channel is not evidence of broken hardware.

Verify the request, not just the branding

Our earlier Trezor investigation examined customer information retained by a shipping provider. This incident is separate. Its mechanism is the misuse of a company’s communication channel to solicit secrets.

The practical lesson is not to abandon self-custody. It is to verify unexpected security instructions independently, through a known official application or support route—not through the message demanding action.

A hardware wallet protects keys. It cannot make a fraudulent request trustworthy.