洞察

analysis / market analysis

Trezor/Brevo钓鱼事件说明:今天“Official Email”已经不能证明信息是真的

Trezor第三方Email Provider Brevo发生Security Incident,攻击者通过可信Infrastructure向约34.7万Newsletter Subscriber发送Phishing Email。事件说明Crypto Security必须验证“要求你做什么”,而不能只验证“谁发来的”。

发布于 2026-09-12更新于 2026-09-12约 8 分钟

Hardware Wallet的设计目标是:

让Private Key即使面对Online Attacker也能保持安全。

但Trezor最新Phishing Incident说明:

Attacker并不一定需要攻破Wallet。

有时只需要攻破User信任的Communication Channel。

Trezor表示,它用于Newsletter Campaign的第三方Marketing Platform Brevo在9月9日发生Security Incident。

Unauthorized Actor获得Brevo Infrastructure Access,并通过被攻破的Customer Account——其中包括Trezor——发送Phishing Email。

Trezor表示,大约34.7万个Newsletter Email Address应该被视为可能已经被Attacker掌握。

Phishing Email谎称Trezor Device受到“STM32 Entropy Vulnerability”影响,并要求User下载Malicious Application,再输入Wallet Backup。

Trezor明确表示:

它自己的Wallet Infrastructure和Internal System没有被攻破。

这是一个非常关键的区别。

这不是Hardware-wallet Exploit。

而是:

Trust-channel Exploit。

为什么这比普通Fake Email更危险?

大部分Phishing Education第一条都是:

检查Sender。

但今天这已经不够了。

如果Attacker直接攻破Legitimate Email-service Account:

它可以通过User本来就信任的Infrastructure发Message。

Email看起来是真的。

Sender也可能看起来是真的。

一些普通Email-security Control甚至不容易拦截,因为Communication来自真实Service Relationship。

Attacker不只是在Impersonate Brand。

它短暂使用了Brand真实Communication Stack的一部分。

Security Model因此发生变化。

Recovery Phrase才是最终Trust Boundary

Trezor最重要的Security Rule仍然非常简单:

Legitimate Wallet Provider不应该要求User把Wallet Backup或者Recovery Phrase输入Website或者下载的Application。

这个Rule比Email Authenticity更可靠。

Attacker可能攻破Newsletter Provider、Support Account、Advertising Account、Social-media Account、Domain,甚至Search Result。

但只要User坚持:

Recovery Phrase不离开Trusted Recovery Process,

Funds仍然可以获得最后一道保护。

所以Wallet Security Education应该减少“教User识别所有Fake Message”。

增加:

“哪些Action永远不应该被要求?”

Third-party SaaS现在已经属于Custody Risk

Trezor Device可以是Secure的。

Trezor Customer同时仍然可以Exposure。

两者并不矛盾。

Crypto Company依赖大量External System:

Email Provider、Support Software、Logistics Company、Analytics Tool、Payment Processor、Cloud Infrastructure。

每一个Vendor都可能成为Attack Surface。

这就是Digital Supply-chain Risk。

Private Key可以被Hardware保护。

但Customer Identity、Email和Behavioral Trust可能通过Marketing Vendor暴露。

所以对于Security-sensitive Company:

Vendor Risk本身已经是Product Security的一部分。

Why it matters

这次Incident说明Crypto Security已经不能只问:

“Wallet被Hack了吗?”

更好的Framework应该问:

  1. Key-management System是否被Compromise?
  2. Customer Data有没有Exposure?
  3. Trusted Communication Channel有没有被Compromise?
  4. Attacker能不能Reuse这些Identity Data?
  5. Future Phishing会不会更Targeted?

Trezor表示Brevo并不保存Wallet Data或者Password。

这是好消息。

但34.7万个“对Trezor感兴趣的Email Address”本身就是高价值Targeting Information。

这些地址可以被继续利用。

所以Initial Phishing Campaign可能只是Risk的第一阶段。

Legitimate Domain不代表Instruction Legitimate

这是最重要的User Lesson。

Security Education经常告诉User:

Verify Domain。

Verify Sender Address。

这些方法仍然有价值。

但不能被当成充分条件。

更强的Test是:

一个真正的Hardware-wallet Company,为什么会需要我在这里输入Recovery Phrase?

如果答案是不应该:

那无论Email看起来多Official,都应该停止。

这是Behavioral Verification Model。

Attacker更难绕过,因为它必须说服User违反最基础的Security Rule。

Vendor Concentration会创造Correlated Risk

Brevo服务很多Organization。

Shared SaaS Infrastructure如果出现Vulnerability:

可能一次Exposure多家公司。

这和直接攻破单一Crypto Company不同。

Attack可以通过Vendor Concentration快速Scale。

相同逻辑也适用于Cloud Provider、Identity Provider、Customer-support Platform、Payment Processor。

Crypto Company在Protocol Layer强调Decentralization。

Operational Layer却高度依赖Centralized SaaS。

这种Mismatch值得被更多关注。

风险与反方观点

不能把这次事件描述成:

“Trezor Hardware Wallet被Hack”。

Trezor明确表示Wallet Infrastructure没有被Compromise。

同样:

只Click Malicious Link并不自动意味着Funds已经被盗。

真正关键Risk是:

User有没有把Recovery Phrase输入Attacker-controlled Application。

另外,也不能确认34.7万个Email全部都被下载或者后来被Reuse。

Trezor采取的是Conservative Assumption:

把它们全部当成可能已被Attacker掌握。

What to watch next

接下来重点看Brevo Root-cause Analysis、是否还有更多Customer Account被影响、更多Crypto Brand是否Disclosure Exposure、Follow-on Phishing Campaign、Confirmed Fund Loss、Trezor Vendor-security Requirement是否变化、Marketing Platform Authentication Control,以及这些Email是否出现在Criminal Market。

最重要的Conclusion不是:

Hardware Wallet失败了。

它没有。

真正重要的是:

Trusted Communication可以失败,而Wallet本身仍然安全。

Crypto Security最终不能只验证Sender。

必须验证:

它要求你做什么。

FAQ

Trezor本身被Hack了吗?

Trezor表示没有。Incident发生在第三方Newsletter Provider Brevo。

影响多少Email?

Trezor表示大约34.7万个Newsletter Address应该被视为可能已被Attacker掌握。

Phishing Email要求用户做什么?

下载Malicious Application并输入Wallet Backup / Recovery Phrase。

只Click Link就会丢钱吗?

Trezor表示Critical Risk来自输入Recovery Phrase,单纯点击并不等于Funds已经Compromise。