The security email was the attack
Attackers used a newsletter provider’s access to send convincing wallet warnings. The failure was outside the hardware wallet—but the message tried to get inside it.

The email asked readers to protect their bitcoin. Following its instructions was the danger.
Trezor says attackers used its newsletter account to send a false hardware-security warning directing recipients toward an application that requested their wallet backup. Its September 10 disclosure puts the mailing at roughly 347,000 recipients. That is a recipient count, not a count of stolen wallets.

Method
Unchanged source-published example. No visible URL or QR code. Illustrates the deceptive request, not a verified hardware defect.
A familiar sender was not enough
Brevo’s post-mortem describes an access-control failure. An attacker configured single sign-on, invited other users, and obtained access beyond the organization that should have bounded that login.
Brevo says 138 accounts were accessed, with six used for phishing emails and contact exports from 43. Those categories should not be added together: the notice does not establish that they are mutually exclusive. The provider also confirms the messages travelled through legitimate infrastructure and passed ordinary email-authentication checks.
This was not simply an unfamiliar address wearing a familiar logo. The sending system itself had become part of the attack.

Method
Original SG explanatory schematic from cited statements. Not a complete exploit reconstruction or a measurement of wallet losses.
Different requests, the same borrowed trust
CoinTracking’s warning describes a different lure: an urgent request to refresh API keys. The company says the incident was confined to its external email service, which held neither those keys nor customer portfolio data. The fraudulent message tried to persuade recipients to supply information the attacker did not already possess.
For Trezor users, the requested secret was a wallet backup. Trezor says its products and account systems were not compromised, and its notice does not establish that its newsletter list was exported. Those limits matter. A compromised mailing channel is not evidence of broken hardware.
Verify the request, not just the branding
Our earlier Trezor investigation examined customer information retained by a shipping provider. This incident is separate. Its mechanism is the misuse of a company’s communication channel to solicit secrets.
The practical lesson is not to abandon self-custody. It is to verify unexpected security instructions independently, through a known official application or support route—not through the message demanding action.
A hardware wallet protects keys. It cannot make a fraudulent request trustworthy.