347,149 Emails and One Reused Seed: Self-Custody's Weakest Link Isn't the Chip

Trezor lost 347,149 customer email contacts through a breach at its email vendor. D'CENT is investigating unauthorized transfers from users who typed their recovery phrase into a phone app. Neither hardware device was broken, which is exactly the problem.
What if your hardware wallet is working exactly as designed, and you still lose everything?
That's the question two separate incidents put on the table this week, and the answer is uncomfortable for anyone who thinks a secure chip and a laminated seed card settle the matter. The device held. The people and systems around the device didn't.
Neither company has reported a compromise of its hardware security. Read that sentence again and notice how little comfort it provides.
The Raw Numbers
Start with Trezor. An attacker got inside Brevo, the third-party email provider Trezor uses to run marketing, by exploiting a flaw in Brevo's SAML single sign-on implementation. Brevo says the intruder reached 138 customer accounts. Contact lists were exported from 43 of them, and six were used to send phishing mail through legitimate customer infrastructure. That's why the messages passed normal email authentication checks and looked like they came from a trusted system.
For Trezor, the breach exposed 347,149 marketing email contacts. The payload was a fake critical hardware vulnerability alert that told customers to download an app to fix their device. The app then asked for the wallet backup. About 2,500 recipients reached the malicious domain before Trezor shut it down.
Clicking the link alone didn't move a single satoshi. Typing those twelve or twenty-four words into the fake app did.
Now D'CENT. Unauthorized transfers showed up on Sept. 16. The Korean hardware maker's investigation points at its App Wallet, the phone-based piece of its stack, not the physical device. The exposure criteria are narrow and specific. Wallets whose recovery phrases were manually typed into the App Wallet, and that had transaction-signing history on builds older than 8.1.0. The blast radius runs across Bitcoin, Ethereum, XRP Ledger, Tron, and other EVM-compatible chains.
Connecting a D'CENT device to the app normally doesn't copy the phrase onto the phone. Importing those words by hand does. D'CENT is telling affected users to update before signing anything else, generate a brand new recovery phrase, and move assets off the old wallet rather than restoring it somewhere new. The company is working with exchanges, law enforcement, and chain analysts to trace and potentially freeze what's already gone.
Why This Is Bigger Than One Bad Week
Self-custody has always had a boundary problem, and it's the boundary nobody wants to talk about at conferences.
The device is the easy part. Secure elements, air-gapped signing, open firmware, hardware vendors have gotten genuinely good at this over a decade of iteration. The Lindy effect is on their side. Chips that survived 2014 and 2018 and 2022 keep surviving, because the math underneath them doesn't care about sentiment.
But the seed phrase doesn't live on the chip. It lives in a person's head, or on a steel plate, or worse, in a note-taking app, or typed into a companion wallet because signing on a phone is more convenient than plugging in a USB cable. Every one of those moves drags the most sensitive string in crypto out of the hardened environment and into a soft one.
And here's the part that should bother you. An attacker who steals 347,149 verified email addresses hasn't just won one campaign. That list is an appreciating asset. It doesn't expire, it doesn't get patched, and it gets more dangerous with every future firmware release, every migration guide, every support ticket that a legitimate user might expect to receive. The list Trezor lost this week is worth more in 2028 than it was the day it leaked.
This isn't a chip problem. It's a data retention problem dressed up as a marketing problem.
Which raises the question every wallet company should be answering publicly right now. Why does a device maker need a marketing contact list at all?
What Security People Are Saying
Researchers who've watched this arc for years keep landing on the same conclusion. The address book is the attack surface. Trezor already learned a version of this in August, when a shipping-provider incident exposed customer phone numbers and shipping addresses while leaving wallets untouched. Two vendor incidents in a matter of months isn't bad luck. It's a pattern.
Trezor's response has been to suspend its Brevo account and review vendor relationships and security requirements. Brevo closed the SSO route the attacker used, reset active sessions, and says it's shipping a permanent fix that restricts authentication to the organization owning each SSO configuration. D'CENT says it's adding safeguards and pre-release verification procedures while its investigation continues. All reasonable. None of it retroactively un-leaks a contact list.
Traders and long-term holders I talk to keep saying the same thing. They trust their hardware. They don't trust the companies selling it to run a database.
Hard money outlasts soft promises, and vendor security is one of the softest promises in this industry.
What To Watch
If you meet D'CENT's criteria, act now, not after the next headline. Update the app, generate a fresh seed on the device itself, and sweep the funds. Don't restore the old phrase anywhere. A phrase that touched compromised software is burned, no matter how clean the next device is.
Watch for a second wave of Trezor phishing. The first domain is dead, but the contact list isn't. Expect messages tied to firmware updates, support follow-ups, and account verification prompts over the next six to twelve months, and expect them to be better written than the first attempt.
Watch the Korean side closely. If exchanges manage to freeze a meaningful portion of the D'CENT transfers, it strengthens the argument that traceability is a real defense. If they don't, it's another data point that on-chain recovery is mostly a promise made after the fact.
And watch whether wallet makers start publishing vendor lists and SOC 2 attestations the way exchanges publish proof of reserves. Data minimization is a product feature now. The first company to compete on it wins trust that's worth more than any marketing list they'd have to give up.
Custody was never a product you buy once. It's a practice you keep. Bitcoin is a mirror. It reflects what you bring to it, and lately, what a lot of people are bringing is a seed phrase typed into a phone.
The signal persists. The discipline is optional, and that's the whole problem.