Key Points
- An authentication vulnerability in Brevo’s email platform enabled unauthorized access to 138 customer accounts
- Approximately 347,000 Trezor newsletter recipients were targeted with a sophisticated phishing campaign
- Hardware wallet companies BitBox and CoinTracking also fell victim through compromised Brevo accounts
- Roughly 2,500 individuals clicked the malicious link before Trezor disabled the fraudulent domain in under 20 minutes
- According to Trezor, no user wallet information, credentials, or core product infrastructure was breached
An authentication weakness in Brevo’s email marketing service enabled a malicious actor to infiltrate 138 customer accounts and distribute phishing emails to hundreds of thousands of cryptocurrency platform users.
The security incident impacted Trezor, BitBox, and CoinTrackingāthree cryptocurrency companies that relied on Brevo’s platform for managing their email subscriber communications.
The Exploitation Method
The threat actor established a Brevo account, activated single sign-on functionality, and sent invitations to authentic Brevo platform users to join the configuration. A critical authorization boundary vulnerability subsequently provided the attacker with entry to all organizations accessible by those invited individuals.
Brevo’s subsequent investigation revealed that phishing emails originated from six compromised accounts, contact information was extracted from 43 accounts, and 93 additional accounts displayed no substantial malicious activity.
The assault was engineered to circumvent standard email verification protocols, causing the fraudulent messages to appear legitimate to those who received them.
The Phishing Email Targeting Trezor Users
An email with the subject line “Critical Security Alert: STM32 Entropy Vulnerability” was distributed to Trezor’s 347,000 newsletter subscribers.
The fraudulent message included a hyperlink directing users to a counterfeit application designed to harvest wallet recovery phrases, which would provide attackers with complete control over victims’ cryptocurrency holdings.
Trezor successfully deactivated the malicious domain through DNS-level intervention within 20 minutes of identifying the phishing campaign. However, approximately 2,500 users had already interacted with the link during this window.
Trezor emphasized that its Brevo account contained exclusively opt-in newsletter email addresses. No user passwords, wallet credentials, or additional sensitive data was maintained within that system.
The hardware wallet manufacturer is now operating under the assumption that all 347,000 email addresses may be known to the attacker and remain vulnerable to additional targeted phishing efforts.
BitBox and CoinTracking Incidents
BitBox reported that the unauthorized email distribution appeared to target its complete newsletter subscriber base and tutorial mailing list via the Brevo platform. The company’s investigation uncovered no indication of contact database downloads, stolen cryptocurrency funds, or compromised recovery seed phrases.
BitBox verified that only subscriber email addresses and language preference settings were stored within its Brevo infrastructure.
CoinTracking’s compromised Brevo account was exploited to distribute an email with the subject line “Data Breach Notice: Please refresh API Keys as soon as possible.” The platform urged its users to avoid clicking any hyperlinks contained within that fraudulent message.
Trezor has terminated its Brevo account access and implemented alert notifications throughout its website interface, mobile application, and customer support platforms.
Users who submitted their wallet recovery phrases after clicking the malicious link should immediately transfer their cryptocurrency assets to a newly generated wallet. Simply clicking the link without providing any information does not compromise fund security.
Trezor announced it is conducting a comprehensive evaluation of its third-party vendor partnerships and security protocols in response to this incident.





