TLDR
- An attacker exploited a login flaw in email platform Brevo to access 138 client accounts.
- Phishing emails reached about 347,000 Trezor newsletter subscribers using a fake “STM32 Entropy Vulnerability” alert.
- BitBox and CoinTracking accounts on Brevo were also used to send fraudulent messages to subscribers.
- Brevo closed the security gap within two hours and reset all user sessions on the platform.
- About 2,500 people clicked the phishing link before Trezor disabled the domain.
A security flaw in the email marketing platform Brevo allowed an attacker to send phishing emails to hundreds of thousands of cryptocurrency users this week. The breach affected newsletter subscribers of hardware wallet makers Trezor and BitBox, along with crypto tracking service CoinTracking.
Brevo confirmed the incident in a postmortem report published Thursday. The company said the attacker gained access to 138 client accounts on its platform.
Six of those accounts were used to send phishing emails directly to subscribers. Contact lists were exported from 43 accounts. The remaining 93 accounts showed no signs of unauthorized activity.
How the Attacker Gained Access
The attacker created a new Brevo account and turned on single sign-on for it. They then invited real Brevo users into that sign-on setup.
Using their own identity provider, the attacker could sign in as those invited users. This is normal behavior for single sign-on systems.
The problem was that access was not properly limited. Instead of staying within one organization, the access spread to every account those invited users could reach.
Brevo said it closed the entry point by 8:30 AM UTC on September 10, about two hours after the issue was found. All active user sessions were reset at the same time.
Crypto Firms Respond to the Breach
Trezor told Cointelegraph the phishing email reached 347,000 subscribers. The message carried the subject line “Critical Security Alert: STM32 Entropy Vulnerability” and linked to a fake app asking for wallet backup phrases.
Trezor disabled the domain at the DNS level within 20 minutes of discovering the attack. Still, around 2,500 people clicked the link before it was taken down.
A Trezor spokesperson said the company is treating all 347,000 addresses as compromised. The Brevo account only stored opt-in newsletter emails, not other customer data.
BitBox confirmed its own newsletter and tutorial subscriber list was hit with a similar unauthorized email. The company said Brevo only held email addresses and language preferences for its account.
BitBox found no signs that company credentials were stolen or that recovery phrases were exposed. It is still treating its list as potentially accessed while it waits for more data from Brevo.
CoinTracking also reported an unauthorized email sent through its Brevo account. The message was titled “Data Breach Notice: Please refresh API Keys as soon as possible” and told recipients not to click any links inside it.
Brevo said the phishing emails passed normal authentication checks because they came through legitimate infrastructure. This made the messages harder for spam filters and users to catch.
The company has disabled all links in the fraudulent emails. It is also building a permanent fix to keep sign-on access limited to the organization that set it up.
Brevo said it is filing a legal complaint over the incident. The company added that it is cooperating with authorities and apologized to affected clients.



