What is confirmed
Trezor says the 9 September incident involved newsletter provider Brevo and that 347,149 marketing contacts were exported via its API.
An email from that channel promoted a fake app asking for wallet recovery words. Trezor says its products and wallets were not compromised.
What it means
An apparently credible sender is not enough: a compromised mailing provider can send through a normally legitimate channel.
The number of exported contacts is not the number of stolen wallets. Direct risk to funds depends in particular on whether recovery words were entered.
What to do
Do not use the email's links. Open the official app through a bookmark and review Trezor's published safety notices.
If you entered recovery words into a third-party app or website, follow Trezor's official instructions immediately to move assets to a new safe wallet.
Use the related SecurCheck tool, then confirm important decisions with an official source.



