Brevo login flaw enabled phishing email targeting 347K Trezor subscribers

Brevo login flaw enabled phishing email targeting 347K Trezor subscribers img1
Spread the love

Written by Ezra Reguerrastaff writerReviewed by Yohan Yunstaff editor

Written by Ezra Reguerrastaff writer

Reviewed by Yohan Yunstaff editor

Brevo login flaw enabled phishing email targeting 347K Trezor subscribers

Latest NewsPublishedSep 11, 2026

Trezor told Cointelegraph that the phishing email was sent to 347,000 subscribers and stated it is treating every address as “known to the attacker and possibly reusable for phishing.”

An attacker exploited a flaw in email platform Brevo’s login system to access 138 client accounts, enabling a phishing email to reach roughly 347,000 Trezor newsletter subscribers and similar fraudulent messages to be distributed through accounts belonging to hardware wallet maker BitBox and crypto portfolio tracking and tax-reporting platform CoinTracking.

In a Thursday postmortem, Brevo stated six accounts were used to send phishing emails, contacts were exported from 43 and 93 accounts showed no meaningful activity. The platform did not specify whether the categories overlapped. 

The attacker created a Brevo account, enabled single sign-on and invited legitimate Brevo users into the configuration. Brevo stated access should have been confined to that organization, but an authorization boundary failed and granted access to every organization the invited users could reach.

The disclosure expands on warnings issued by Trezor and BitBox on Wednesday, identifying their shared provider and explaining why the emails passed normal authentication checks and appeared genuine. 

Cointelegraph reached out to Brevo for more information but did not receive a response before publication. 

Crypto firms assess potential subscriber exposure 

In a blog post, Trezor stated the phishing message, titled “Critical Security Alert: STM32 Entropy Vulnerability,” contained a link to an app that requested users’ wallet backups. The company disabled the domain at the DNS level within 20 minutes, but about 2,500 people accessed the link before the takedown.

A Trezor spokesperson told Cointelegraph that “the initial email was sent to 347,000 customers,” all of whom were subsequently contacted about the risk. The company’s Brevo account stored only opt-in newsletter email addresses and no other customer data.

“Until we hear more from Brevo, we are treating all roughly 347,000 newsletter addresses as known to the attacker and possibly reusable for phishing,” the spokesperson stated.

Related: Liquid Network resumes block production after $320M exploit

A BitBox spokesperson told Cointelegraph that its unauthorized email was sent through Brevo and appeared to have reached its full newsletter and tutorial list. 

BitBox stated Brevo held only email addresses and language preferences. It found no evidence of compromised company credentials, downloaded contacts, lost funds or disclosed recovery phrases, but is treating the list as potentially accessed while awaiting Brevo’s logs.

Meanwhile, CoinTracking stated its Brevo account distributed an email titled “Data Breach Notice: Please refresh API Keys as soon as possible.” It warned recipients not to follow the email’s links.

Magazine: 10 of the greatest unsolved crypto mysteries

1 minute letter

1 minute letter

Subscribe to daily byte-sized crypto news from Cointelegraph

Subscribe

Cointelegraph is committed to independent, transparent journalism. This news article is produced in accordance with Cointelegraph’s Editorial Policy and aims to provide accurate and timely information. Readers are encouraged to verify information independently.

  • Phishing
  • Email
  • Trezor
  • Wallet
  • Hardware Wallet
  • Hackers
  • Scams & Cybercrime

More on the subject

Liquid Network resumes block production after $320M exploit



12 hours ago

Nate Kostar

US sanctions Xinbi scam marketplace, restrains $52M in crypto



Sep 10, 2026

Ezra Reguerra

Cybercrime ringleader Malone Lam pleads guilty in $245M crypto theft conspiracy



Sep 9, 2026

Ezra Reguerra

Liquid Network resumes block production after $320M exploit



12 hours ago

Nate Kostar

US sanctions Xinbi scam marketplace, restrains $52M in crypto



Sep 10, 2026

Ezra Reguerra

Cybercrime ringleader Malone Lam pleads guilty in $245M crypto theft conspiracy



Sep 9, 2026

Ezra Reguerra


💡 A Greener Way to Earn: Looking for a smarter, more sustainable way to earn and mining crypto? EcoPool Network is a cloud-based mining pool that does the heavy lifting on remote servers — so you earn rewards around the clock without worrying about overheating hardware or sky-high electricity bills. It’s lightweight, battery-friendly, and built for everyday users. Download EcoPool now and start mining & earning smarter today.

Spread the love

About the Author

Leave a Reply

Your email address will not be published. Required fields are marked *

You may also like these