Trust is a liability, not an asset. Trezor learned this three times in one summer.
The mechanics were not exotic. No secure element was decapped. No private key was factored. Attackers took control of a third-party email domain, then spoke to Trezor users in Trezor's own voice. The subject line read "STM32 Entropy Vulnerability." The domain was pulled once the company noticed. An official warning tweet went out. None of that erases a seed phrase already typed into a phishing page.
By the time the second incident surfaced, the reported blast radius of a logistics leak had been revised from 13,689 users to more than 80,000. Three incidents. One summer. Zero of them touching the hardware.
That asymmetry — the device intact, the perimeter gone — is the whole story. Anyone reading it as a story about cryptography is reading the wrong document.
Context
Trezor is the original consumer hardware wallet. Its parent, SatoshiLabs, has shipped open-firmware devices since 2014 out of Czechia, and the product line has become shorthand for self-custody itself. The pitch is simple and, for a decade, durable: the seed never touches an internet-connected machine, so the attack surface shrinks to physics.
That pitch quietly assumed a trust boundary it never drew. Between the user and the device sits a supply chain — logistics, email, customer support, marketing automation — every one of which handles some slice of user identity. The device protects the key. It does not protect the person.
Two vendors sit at the center of this summer's events. ShipMonk, a logistics fulfillment provider, held shipping records: names, addresses, phone numbers, order histories. Brevo, a transactional email platform, held the ability to send mail originating from Trezor's domain. Both roles are classified under EU law as processors; Trezor is the controller. The controller is the one on the hook.
ShipMonk's exposure is the more embarrassing. A 90-day data retention policy was pledged and, per the disclosure trail, not honored. Recycled personal data from a vendor that promised deletion is not a hack — it is a contract failure that became a breach.
Brevo's exposure is the more dangerous. Domain-level control is not what you get by guessing passwords. Reaching the level where you can send authenticated mail as Trezor implies privileged credentials, API abuse, or a long dwell inside the vendor. Any of those three is a decision, not an accident. Code does not lie, but incentives often do — and a marketing vendor optimizing for deliverability has no incentive to over-invest in the security of a client's domain lock.
The phishing itself was not mass-market spam. It was surgical.
Core
Start with the lexicon. "STM32 Entropy Vulnerability" is not a phrase a script kiddie generates. STM32 is the microcontroller family used in a subset of embedded wallets. Entropy is the wellspring of every seed phrase ever generated. Pair those two words in a subject line and you filter instantly for users who understand their own threat model — the exact cohort most likely to hold meaningful balances and least likely to dismiss the mail as noise.
I have seen this movie before. In 2017, I audited the whitepapers of forty-plus ERC-20 projects, and the ones that failed my checklist almost always failed for the same reason: the visible code was competent while the invisible incentives were wrong. Vesting schedules that looked clean on a chart, liquidity arrangements that dissolved on contact. This campaign is the phishing version of the same lesson. The email looked competent. The infrastructure beneath it was not.
Now watch the reproduction. The same "microcontroller entropy" framing surfaced against BitBox users inside the same window. That is not coincidence; it is a shared playbook. Attackers do not reinvent vocabulary per target. They industrialize it.
And they can, because the targets share a spine. Brevo is not Trezor's vendor. Brevo is an industry vendor. BitBox used it. CoinTracking used it. Peach Bitcoin used it. Blocktrainer used it. At least five crypto-facing companies sat on the same email rails. Brevo's compromise is not a Trezor story with a wide lens. It is a shared attack surface story that happens to include Trezor.
This is the part that deserves cold attention. A single email processor breach can simultaneously ignite phishing campaigns against several hardware wallet brands, a portfolio tracker, and one of the largest German-language Bitcoin media outlets. That is not vendor risk. That is systemic risk wearing a vendor's badge.
Trace the kill chain and the discipline is visible. Reconnaissance harvests the vendor relationship — trivial, because privacy policies publish it. Compromise targets the vendor, not the client. Domain control neutralizes SPF, DKIM, and DMARC in one stroke, because authentication only proves a domain's owner sent the mail; it says nothing about whether the sender is trustworthy. Distribution then runs through the client's verified pipeline. Harvest follows. Every stage is cheap except the one that matters, and that one sits outside the client's audit scope.
The paradox underneath is uncomfortable for anyone who preaches self-custody. Private keys are decentralized across millions of devices. Identity data is centralized in a handful of SaaS contracts. The key layer is sovereign. The person layer is a marketing database with a 90-day retention promise that apparently had an asterisk.
Move up the stack and the same architecture recurs. In 2020, I led an analysis of Curve and SushiSwap yields and argued that DeFi's headline APRs were liquidity subsidies dressed as market efficiency. Yield without basis is just delayed liquidation. Substitute "breach" for "liquidation" and the logic holds: trust without audit is just a delayed incident. The Trezor brand was the subsidy. The vendor contracts were the basis. The basis was thin.
In 2024, mapping spot ETF inflows, I watched a single structured product stabilize an entire asset class by relocating liquidity into regulated rails. The lesson cut both ways. Concentration creates efficiency and creates a short, definite list of nodes worth attacking. Brevo is a node. ShipMonk is a node. That list is finite, and it is public to anyone who reads a privacy policy.
The compliance layer follows from the same structure. Under GDPR, a controller is not excused by a processor's failure. Trezor cannot say "ShipMonk did it" and close the file. The 72-hour notification duty runs uphill to the controller. A retention policy breached by a vendor is a controller's supervisory failure. For a Czech-domiciled company operating across the EU, that is not a footnote; it is a docket entry waiting to be written.
Competitively, the field has already moved. Ledger, Keystone, and Coldcard inherit a narrative they did not earn — "we were not on Brevo." BitBox was on Brevo, which blunts the obvious migration. And self-custody switching costs are real: buy a new device, re-derive, re-secure, re-test. Users grumble for a quarter and mostly stay. Stability is a feature, not a market condition — and hardware wallet share is stable precisely because the switching friction is structural, not because the field is safe.
For users, the operational rule is binary. A seed phrase entered anywhere other than the physical device is already compromised — there is no legitimate entropy re-verification, no emergency migration, no support-driven backup request. Attackers know most people learn this rule exactly once, and they are betting the lesson is expensive. Never spend the lesson twice.
The sting remains reserved for people, not companies. Attackers who can match an email address, a shipping record, and an order history are running a precision funnel. The realistic downside is not a slumping quarter. It is a phone call, a doorstep, or a seed phrase surrendered on the fourth attempt. Liquidity is the only truth in a vacuum of trust — and in this scenario, the most liquid thing in the room is the victim's balance.
Contrarian
The loud takeaway is "hardware wallets are broken." It is wrong, and the wrongness is precise. No cryptographic primitive failed. No secure element leaked. The device did what it was designed to do and would do it again tomorrow.
But the reflexive counter-takeaway — "self-custody is fine, users just need to be careful" — is equally unserious. It relocates blame to the one party with the least leverage. Users cannot audit their vendor's domain lock. They cannot verify a 90-day retention clause. They cannot tell an authenticated spoof from an authenticated send when both arrive signed.
Notice also what the industry's own response reveals. When five companies discover they share one compromised mailbox, the rational move is coordination — a shared vendor security rating, a common blacklist, a joint audit pool. None of that exists yet, because it would require competitors to publish the parts of their stack they prefer to keep quiet. The silence is the tell.
The honest reading is narrower and harder. Trezor's failure is a governance failure at the boundary where a security brand outsourced its identity layer while selling sovereignty at the key layer. That mismatch is the vulnerability. Not the chip. Not the user. The gap between what was secured and what was promised.
Takeaway
Watch three things: whether a fourth incident lands before the year closes, whether Brevo retains its crypto clients, and whether EU regulators treat the retention lapse as a controller failure or a vendor one. The answer to the third will set the template for every hardware wallet's vendor contract for years.
The cold question for this cycle is not whether self-custody is safe. It is whether the companies selling it will finally price the trust boundary they have been borrowing for free.