Hardware crypto wallet company Trezor has issued a second warning to its customers in as many months about a security breach involving a third-party company it uses. In a recent blog post, Trezor explained that a cyberattack on Brevo, a marketing technology firm used to send newsletters, allowed hackers to send approximately 347,000 phishing emails to its users. These emails contained a malicious link that appeared to be from Trezor itself, prompting recipients to download an app that would request their wallet backup password. One of the email subject lines was "Critical Security Alert: STM32 Entropy Vulnerability," a tactic designed to trick users into believing the message was urgent and legitimate. Brevo confirmed in its own incident report that hackers accessed 138 of its accounts to send the phishing emails. The company explained that the breach occurred because the hackers exploited a flaw in their access permissions—specifically, that their access was "not properly scoped" and "wrongly granted" to all organizations the hackers' accounts could reach. This type of security vulnerability is not uncommon, particularly when companies rely on third-party services to handle customer communications or data. Trezor emphasized that its own products, wallet systems, and account infrastructure were not compromised in this incident. This is the second time in recent weeks that Trezor has warned customers about a breach involving one of its partners. Earlier in August, it alerted users that ShipMonk, a shipping provider, had been hacked, exposing personal information such as names, phone numbers, email addresses, and postal addresses of at least 81,000 individuals who had purchased Trezor hardware wallets. This type of breach can put cryptocurrency holders at risk of targeted attacks, including so-called "wrench attacks," where individuals are physically threatened to obtain their passwords. In the weeks after the ShipMonk breach, some users reported receiving physical mail that appeared to be from Trezor, containing a QR code that led to a fake website attempting to steal their wallet passwords. In response, Trezor has said it is reevaluating its relationships with its vendors and has warned customers that their email addresses may be used again in future phishing attempts. The company encourages users to remain vigilant and to verify the authenticity of any communications they receive.