2026-09-11 CoinTelegraph

Brevo Login Flaw Exposed 347K Trezor Users in Phishing Attack

A vulnerability in email marketing platform Brevo's login system was exploited to send phishing emails to approximately 347,000 Trezor newsletter subscribers, with similar attacks hitting hardware wallet maker BitBox and crypto tax platform CoinTracking. According to Brevo's Thursday postmortem, an attacker created a Brevo account, enabled single sign-on, and invited legitimate users into the configuration. An authorization boundary failure then granted access to every organization those invited users could reach, compromising 138 client accounts in total. Of those, six accounts were used to send phishing emails, contacts were exported from 43, and 93 showed no meaningful activity.

Trezor confirmed the fraudulent message, titled "Critical Security Alert: STM32 Entropy Vulnerability," contained a link to a fake app requesting users' wallet recovery seeds. The company disabled the malicious domain at the DNS level within 20 minutes, but roughly 2,500 recipients clicked the link before takedown. "Until we hear more from Brevo, we are treating all roughly 347,000 newsletter addresses as known to the attacker and possibly reusable for phishing," a Trezor spokesperson told Cointelegraph. The company's Brevo account stored only opt-in newsletter email addresses and no additional customer data.

BitBox reported that its unauthorized email reached its full newsletter and tutorial subscriber list, though Brevo held only email addresses and language preferences for the company. BitBox found no evidence of compromised company credentials, downloaded contact lists, lost funds, or disclosed recovery phrases, but is treating the subscriber list as potentially accessed while awaiting Brevo's full investigation. The breach is particularly concerning because the phishing emails passed standard authentication checks, including DKIM and SPF signatures, making them appear legitimate to recipients and email security filters alike.

The incident highlights the supply chain vulnerabilities inherent in shared SaaS providers used across the crypto industry. A single flaw in a third-party email platform compromised multiple hardware wallet and crypto service providers simultaneously, exposing hundreds of thousands of users to targeted phishing. Users who interacted with the Trezor phishing link are urged to assume their recovery seeds are compromised and transfer funds to new wallets immediately.

Read Full Article at CoinTelegraph →

Related Tool

Find Your ID

Try Now →
Check My ID