# A Real Sender Can Still Carry a Fake Emergency

> A compromised newsletter service sent a false Trezor warning through a genuine mailing route. Here is the wallet-backup rule that works even when the sender looks right.

- **Author:** Kubilay Tunca
- **Published:** 2026-09-11
- **Category:** For Mortals
- **Tags:** Online Safety, Phishing, Cryptocurrency, Scam Awareness
- **Canonical URL:** https://cyber-security-in-plain-english.com/post/mortals/news/real-sender-fake-emergency-wallet-backup-rule

---

The email did not arrive from an obvious misspelling of a famous brand. It appeared to come from Trezor’s own newsletter address, warned about a supposed hardware flaw, and offered an urgent route to protect a cryptocurrency wallet. For somebody who had bought a hardware wallet precisely because they cared about security, the message pressed the right button: act now, before the safety device fails you.

The flaw described in that email was false. The sending route was real.

On 9 September 2026, an attacker used access to Brevo, the outside marketing platform that Trezor used for newsletters, to send the message to roughly 347,000 subscribers. The link led people towards an application that asked for their wallet backup, the list of words that can recreate the wallet. Trezor says it disabled the domain within 20 minutes, but about 2,500 people had already clicked ([Trezor](https://trezor.io/blog/news/security-incident-at-brevo-our-third-party-email-provider); [The Register](https://www.theregister.com/cyber-crime/2026/09/10/trezor-bitbox-users-targeted-in-newsletter-phishing-spree/5295496)).

Here is the useful lesson, and it reaches beyond cryptocurrency. A familiar sender can help you judge an ordinary message, but it cannot approve the request inside that message. When an email asks for a secret, a payment, an installation, or a security change, judge the action separately. In this case, one rule settles the whole question: a wallet backup never belongs in a form, website, downloaded app, support chat, or email.

## What happened on 9 September

Trezor’s account, published on 10 September 2026, says an unauthorised person gained access to Brevo’s system and used customer accounts to send phishing emails. Trezor and contemporaneous reporting from The Register both gave the affected Brevo-account count as 120. Trezor’s own newsletter database contained roughly 347,000 opt-in email addresses, and the company said it was treating every one of those addresses as potentially known to the attacker while Brevo’s investigation continued ([Trezor](https://trezor.io/blog/news/security-incident-at-brevo-our-third-party-email-provider); [The Register](https://www.theregister.com/cyber-crime/2026/09/10/trezor-bitbox-users-targeted-in-newsletter-phishing-spree/5295496)).

The message used the subject line “Critical Security Alert: STM32 Entropy Vulnerability.” It claimed that a hardware defect had weakened the randomness protecting some devices. That language sounds forbidding because most owners cannot reasonably assess microcontroller entropy over breakfast. The requested cure was easier to understand: follow a link, download an application, and enter the wallet backup.

That cure reveals the fraud. A wallet backup gives its holder the power to reconstruct the wallet and control the funds. Asking for it online is rather like announcing that a lock may be faulty, then offering to fix the problem if you hand over the only master key. The technical story can be polished, accurate-looking, or completely opaque. The handover remains wrong.

Trezor says the malicious domain was disabled at the domain-name-system level within 20 minutes. In everyday terms, the company removed the address that helped browsers find the scam site. It also disabled the email-sending function and placed warnings on its website, wallet application, support pages, and community channels. About 2,500 people reached the link before the takedown, according to the company. That number counts visits, not confirmed losses or surrendered backups.

The distinction matters. Trezor’s 10 September notice says that somebody who clicked but did not enter a wallet backup did not expose funds merely by opening the link. Somebody who entered the backup faces a different emergency and should move the funds to a wallet created with a new backup immediately. Good incident advice separates those two people instead of frightening both with the same headline.

The company also says no Trezor wallet, product, or account system was breached in this incident. Brevo held newsletter email addresses, not wallet data, passwords, or backups. As of 11 September, Trezor said it could not confirm whether the mailing list itself had been exported, so it chose the cautious assumption that the addresses may be reused in later phishing attempts. That creates an ongoing message problem, not evidence that 347,000 wallets were opened.

The Register reported that BitBox subscribers received a closely related false warning and that CoinTracking customers received a different lure asking them to refresh programming keys. Both companies used Brevo for email. The details changed to suit each audience, while the basic move stayed the same: borrow a legitimate communication channel, invent a security problem, then ask the recipient to transfer something valuable ([The Register](https://www.theregister.com/cyber-crime/2026/09/10/trezor-bitbox-users-targeted-in-newsletter-phishing-spree/5295496)).

## How a bad message can come through a good address

Most phishing advice starts with the sender line because it is visible and often useful. A message from `trez0r-help.example` deserves suspicion. A message from a random webmail account claiming to be your bank is easy to discard. Those clues catch cheap imitations, and nobody should stop using them.

This incident reached one step further back. A newsletter provider needs permission to send large batches of mail for its customers. The customer gives the service access to a subscriber list, approved branding, and a route that receiving mail systems recognise. That arrangement is ordinary. Running unsubscribe lists, delivery failures, and hundreds of thousands of messages from a home-built mail server would be a poor use of most companies’ time.

Now picture the newsletter provider as a trusted print room. Trezor supplies the paper, letterhead, address list, and authority to post the envelopes. Usually, the print room sends exactly the approved newsletter. If somebody takes control of the print room, they do not have to forge the envelope on a kitchen printer. They can place a false letter inside the normal process.

The Register noted on 10 September that messages sent through the compromised provider could pass authentication checks and some receiving-service protections because the channel itself was legitimate. Email authentication can answer useful delivery questions: was this server allowed to send for the domain, and was the message altered after it was signed? It cannot read the message and decide whether the company truly wants you to surrender a master secret. A passport can establish who carried a parcel. It does not establish that everything inside the parcel is safe.

That limit does not make sender checks pointless. It puts them in the right job. A wrong domain, failed warning, unexpected reply address, or strange attachment can disqualify a message quickly. A clean sender line only means that the message survived that particular check. It earns a closer look, not obedience.

The same problem appears outside newsletters. A real friend’s account can send a scam after the friend loses access. A genuine support mailbox can be misused by an intruder. A supplier’s normal invoice system can send altered bank details. An employee with a compromised account can ask a colleague for a file they should never receive. In each case, the sender may be real enough to pass the first test while the requested action fails the second.

For ordinary life, the second test can stay simple. Ask what the message wants to cross: money leaving an account, a secret leaving your hands, software entering a device, or authority changing from one person to another. The larger that crossing, the less weight you should give to the fact that an email arrived through a familiar door.

## The wallet backup is the wallet’s master copy

A hardware wallet can make cryptocurrency safer by keeping the private signing material away from an ordinary internet-connected computer. You can view a balance in the companion software and prepare a transaction, but the physical device confirms the sensitive action. That separation is the point. A malicious page on the laptop should not gain the same authority as the device in your hand.

The wallet backup, sometimes called a recovery seed or seed phrase, is the escape hatch for a lost or broken device. Trezor explains that the words represent the random value from which the wallet’s keys and addresses are derived. With the correct backup, an owner can restore access on another compatible device ([Trezor](https://trezor.io/guides/backups-recovery/general-standards/how-to-use-a-wallet-backup)).

That recovery power works for whoever has the words. The wallet cannot tell whether they belong to the careful owner, a helpful relative, or a stranger who collected them through a convincing form. A thief who has the full backup does not need the original hardware wallet or its PIN in hand. The backup is therefore closer to a master copy of every key than to an account password that a company can reset.

This is why the false warning aimed at the backup rather than the device. Breaking modern cryptography is expensive and uncertain. Persuading a worried person to type the recovery words into an application can be much cheaper. The attacker wraps the request in a story about safety so that the protective action and the dangerous action appear to be the same thing.

Keep the backup offline and private. Paper or a purpose-built physical backup stored somewhere sensible can survive a damaged device without becoming another file waiting in cloud storage, a photo library, email, or notes. The right arrangement depends on the value involved and the household, but the boundary stays firm: no unsolicited message needs those words.

There is one piece of nuance for owners who remember entering words during legitimate recovery. Some wallet models use the physical device itself for recovery entry. Older workflows may involve carefully documented official procedures. That is not permission to follow instructions delivered by surprise email. Start from the official application or support site that you opened yourself, confirm the exact process for your model, and use the hardware screen where the manufacturer instructs you to do so.

A real support worker should never need your complete wallet backup. Trezor states this plainly in its incident notice: the company will never contact you asking for it. Treat that as a permanent rule rather than a temporary warning attached to one campaign. Staff can help diagnose a display problem, explain a firmware update, or point to a recovery guide without taking possession of the secret that controls the wallet.

If a form asks for all the words, stop. If a downloaded “security tool” asks for them, stop. If a caller offers to check whether they are valid, stop. You do not need to understand the claimed vulnerability, inspect the website code, or win an argument with the sender. The request has already failed.

## Read the request before you investigate the story

The phishing email chose a clever order. It presented a technical emergency first, then offered the action. A recipient who spends ten minutes researching microcontrollers may remain inside the attacker’s frame: something is broken, time is short, and the message contains the route to safety. The more unfamiliar the technical claim feels, the more attractive the simple button becomes.

Reverse the order. Read the requested action first.

Suppose an email says your bank has found a new encryption defect and needs the code that just appeared on your phone. You do not have to investigate the defect before refusing. The code approves a login or payment, and an inbound caller does not get it. Suppose a message from a known supplier announces an accounting-system migration and supplies new bank details. The software story can wait while you call the supplier on a number already in your records.

For the Trezor message, the action was a download followed by entry of a wallet backup. Both steps deserved a pause. Unexpected software asks you to let new code into the computer. A wallet-backup form asks you to let the master copy out. The sender line cannot safely approve either crossing by itself.

The US Federal Trade Commission gives similar advice for unexpected messages that appear to come from a company you know. Rather than using the link or contact information inside the message, contact the company through a website or phone number you know is genuine ([FTC](https://consumer.ftc.gov/articles/how-recognize-avoid-phishing-scams)). That fresh route matters because replying to the email keeps you inside the channel that may already be under somebody else’s control.

A separate route can be very ordinary. Open the wallet application from its usual icon and look for an alert. Type the company’s known address into a fresh browser tab, or use a saved bookmark. Check the status or support page. If the claim concerns a financial adviser or exchange, call a number from a statement or from the official site you navigated to independently.

Search results require a little care during a live campaign. Criminals can buy advertisements or create lookalike support pages around a trending problem. The safest route is one you established before the message arrived: the installed application, a bookmark, packaging you retained, or an address typed and checked carefully. If you search, ignore sponsored shortcuts and inspect the destination before entering anything.

Notice what this approach does for a non-technical reader. It removes the obligation to become a microcontroller expert. You are checking whether the company repeats the warning through a route you chose and whether the requested action fits a standing safety rule. That is a smaller, fairer job.

It also works when the warning turns out to be genuine. Real companies publish serious updates in their normal application and on their official support pages. Opening the known route may take an extra minute, but it still gets you to the fix. A security measure that only works by demanding instant trust in an email would be badly designed.

## Clicking, downloading, and handing over the backup are different events

After a scare, people often compress the whole sequence into one sentence: “I clicked it, so I have been hacked.” That conclusion can lead to panic, rushed transfers, or paying a stranger who claims to offer recovery help. The response should match the furthest action that actually occurred.

Trezor’s advice for this specific incident is unusually clear. As of 10 September 2026, the company said that clicking the link alone did not expose a person’s funds. The reported danger arose if the person entered the wallet backup into the malicious application. This statement applies to the campaign Trezor investigated. It should not be turned into a universal promise that every malicious link is harmless.

A person who saw the email and did nothing can delete it. Their wallet does not need to be wiped or replaced because the message reached the inbox. Since Trezor is treating the newsletter addresses as potentially known to the attacker, that person should expect another convincing approach and keep the same no-backup rule.

A person who clicked but did not download or enter anything should close the page and avoid returning to it. For this incident, Trezor says the funds remain secure if the backup was entered only on the physical device during recovery. Check the company’s warning through the official application or website, then stop. There is no benefit in repeatedly opening the malicious address to see whether it still works.

A person who downloaded an application has another question: did it run? A file that merely landed in the downloads folder differs from one that was opened, installed, or granted permissions. Remove the unopened file. If it ran, disconnect the computer from sensitive financial work, use a trusted device to review the official incident guidance, and get competent help checking the computer. Do not install a second surprise “cleanup tool” advertised in a reply or social-media comment.

A person who entered the wallet backup faces the urgent case. Trezor says to move the funds immediately to a new wallet with a new backup. Use a trusted, clean device and an official wallet process that you reach independently. The new wallet must be based on new recovery words, because moving funds between addresses derived from the exposed backup leaves the thief with the same underlying master copy.

Speed matters here, but improvisation still creates danger. Somebody who is unsure how to create and verify a fresh wallet should seek help through the manufacturer’s official support route without revealing the old or new backup. A genuine helper can explain the sequence while the owner keeps the words private. Anyone asking to “secure” the funds by taking the backup or receiving the coins into a support wallet is extending the scam.

If cryptocurrency has already moved without permission, preserve transaction identifiers, messages, downloaded filenames, and approximate times after taking immediate protective steps. Contact any exchange involved through its official route and report the theft to the appropriate local authority. Blockchain transfers are generally difficult to reverse, so beware of recovery services that promise certainty for an upfront fee.

The emotional part deserves space. People click because the message was built to be clicked, and this one came through a service authorised to send Trezor mail. Shame delays action. If a partner or relative tells you they entered the words, help them create the new wallet first. The lecture can be skipped entirely.

## What Trezor owners should actually do now

Most recipients can finish the useful response in a few minutes. The incident does not require every owner to move funds or replace a device. It calls for one firm rule, a check of what happened, and a clean route to the official notice.

1. **Work out how far you went.** Separate receiving, clicking, downloading, running, and entering the wallet backup. Write down the furthest completed step. Trezor’s current advice makes the backup entry the decisive event for wallet funds in this campaign.

2. **Open Trezor through a route you already trust.** Use the installed Trezor Suite application, a saved official bookmark, or carefully type `trezor.io` into a fresh browser tab. Read the incident notice there. Do not use a button, phone number, reply address, or download supplied by the suspicious email.

3. **Keep the wallet backup offline.** Do not type it into a website, ordinary computer form, support chat, or application reached through a message. Do not photograph it to ask somebody whether it looks right. Trezor support will not ask for it.

4. **If you entered the backup, create a new wallet and move the funds now.** Follow the official procedure from a clean, trusted route and generate a new wallet backup. Keep both sets of words private during the move, then treat the old set as permanently exposed. If you need guidance, official support can explain the process without receiving the words.

5. **If you ran the downloaded application, check the computer separately.** Stop using that machine for wallet or banking work until it has been examined. Review installed applications and security alerts, and seek trusted technical help if you are uncertain. A clean wallet move and a clean computer are separate jobs.

6. **Expect follow-up messages.** Trezor says it is treating the roughly 347,000 newsletter addresses as potentially known to the attacker as of 10 September. A later email may refer accurately to this incident, your newsletter subscription, or the earlier false subject line. Accuracy shows access to context. It does not authorise a request.

7. **Tell the person who shares your finances.** A partner or family member should know that nobody gets the wallet backup, including somebody claiming to be Trezor support. One calm household rule is more useful than forwarding every rumour about the incident.

There are also several things most owners can skip. If you never entered the backup, Trezor’s notice does not call for a new wallet solely because the email arrived. You do not need to answer the sender, test the bad link, pay for a monitoring subscription, or publish a photo of the message with personal details visible. You do not need to understand “entropy” to reject a request for the master key.

Owners who never subscribed may still encounter copies of the message elsewhere. Criminal campaigns get forwarded, screenshotted, and adapted. Apply the same rule. A claimed security emergency does not create a legitimate need for a wallet backup to leave your control.

## The lasting rule is about authority, not appearance

Security advice sometimes promises a visual giveaway: the logo will be fuzzy, the grammar will be wrong, or the address will contain an extra letter. Those signs remain welcome shortcuts when they appear. The Brevo incident shows why they cannot carry the whole decision. A criminal who reaches an authorised sending system may inherit clean branding, a real address, and the technical marks of legitimate delivery.

The request is harder to borrow. A bank does not need your one-time code from an inbound call. A genuine supplier can tolerate a callback before changing payment details. A wallet maker does not need your recovery words. A real software update can be reached from the application or vendor site without following a surprise attachment.

Think of trust as two locks. The first lock asks whether the messenger appears to be who they claim. The second asks whether that messenger should have the power they are requesting. Many scams only need you to check the first lock. Safe action depends on both.

Companies have work to do here too. A customer should be able to verify a warning in the product, on an independently reached status page, and through support. High-risk actions should require a trusted device or an established application rather than an email path. Marketing systems should hold as little customer information as they need, and access to a newsletter should never grant access to wallet secrets or product controls.

Trezor’s response usefully stated what was affected, what was not, how many addresses received the message, how many people reached the link, and what different recipients should do. As of 11 September 2026, Brevo’s complete public account of the intrusion was still developing in the sources reviewed for this post. The known facts justify caution around future messages without justifying claims that every subscriber lost funds or that Trezor’s hardware was broken.

A convincing email arrived through a real door. The safest answer did not require a forensic examination of that door. It required recognising that the person on the threshold was asking for the one key nobody should collect.

Keep the words offline. Open the official route yourself. Then get on with your day.

For calm, practical security guidance without a daily alarm bell, join the newsletter. It is one email per month.

## Sources

- [Trezor: Security incident at Brevo, our third-party email provider](https://trezor.io/blog/news/security-incident-at-brevo-our-third-party-email-provider), accessed 2026-09-11
- [The Register: Trezor, BitBox users targeted in newsletter phishing spree](https://www.theregister.com/cyber-crime/2026/09/10/trezor-bitbox-users-targeted-in-newsletter-phishing-spree/5295496), accessed 2026-09-11
- [Trezor: How to use a wallet backup](https://trezor.io/guides/backups-recovery/general-standards/how-to-use-a-wallet-backup), accessed 2026-09-11
- [US Federal Trade Commission: How to recognize and avoid phishing scams](https://consumer.ftc.gov/articles/how-recognize-avoid-phishing-scams), accessed 2026-09-11

---

## About the author

Kubilay Tunca — Senior Full Stack Developer and Author. Founded Cyber Security in Plain English to translate complex security concepts into clear, practical advice, and writes the accompanying books on security, privacy, secure development, and AI systems.

## Books by this author

- **The Digital Fortress** — Your Everyday Guide to a Safer Digital Life. A warm, plain-English guide for people with real lives and finite patience. Learn the handful of habits that genuinely protect your money, accounts, and family, and get honest permission to ignore the rest. [Amazon](https://buy.cyber-security-in-plain-english.com/digital-fortress) · [Details](https://cyber-security-in-plain-english.com/books/the-digital-fortress)
- **The Anonymity Playbook** — Digital Survival for Whistleblowers, Journalists, Activists, and Everyone Else. A practitioner’s field manual for journalists protecting sources, whistleblowers, and activists. It explains how the surveillance actually works, what each technique costs you, and exactly where it fails. [Amazon](https://buy.cyber-security-in-plain-english.com/anonymity-playbook) · [Details](https://cyber-security-in-plain-english.com/books/the-anonymity-playbook)
- **Secure Software Development** — Practical patterns for building secure software. A hands-on security guide for developers and IT professionals who ship real software. Build, deploy, and maintain secure systems without slowing down or drowning in theory. [Amazon](https://buy.cyber-security-in-plain-english.com/secure-software-development) · [Details](https://cyber-security-in-plain-english.com/books/secure-software-development)
- **The Secure Harness** — Shipping Production Code with AI Coding Agents. A calm, practical guide to letting agents do useful work inside boundaries you set, enforce, and audit. Ships with 15 copy-pasteable artifacts: hook scripts, permission configs, release gates, and MCP templates. [Amazon](https://buy.cyber-security-in-plain-english.com/secure-harness) · [Details](https://cyber-security-in-plain-english.com/books/the-secure-harness)
- **The AI Native Engineer** — Build, Evaluate, and Ship AI Systems That Work in Production. Sixteen hands-on chapters, one real product. Grow it from a single model call into a retrieved, tool-using, observable, production-grade system, with evaluation treated as a habit from the first feature. [Amazon](https://buy.cyber-security-in-plain-english.com/ai-native-engineer) · [Details](https://cyber-security-in-plain-english.com/books/the-ai-native-engineer)

Full catalogue with contents and intended audience: https://cyber-security-in-plain-english.com/books

_As an Amazon Associate I earn from qualifying purchases. Buying through these links costs you nothing extra and helps pay for the blog._
