Brevo, an email delivery platform used across the crypto industry, disclosed that an attacker leveraged a login-system weakness to gain access to multiple client accounts. The incident allowe
Brevo, an email delivery platform used across the crypto industry, disclosed that an attacker leveraged a login-system weakness to gain access to multiple client accounts. The incident allowed phishing messages to be sent to a combined audience of roughly 347,000 Trezor newsletter subscribers, with additional campaigns also reaching audiences tied to BitBox and CoinTracking.
In a Thursday postmortem, Brevo said the attacker used six accounts to send phishing emails. It also reported that contacts were exported from 43 accounts, while 93 accounts showed no meaningful activity—though Brevo did not clarify whether those categories overlap. Brevo added that the access-control boundary that should have limited the attacker’s reach to a single organization failed.
Key takeaways
- Brevo reported that an authorization boundary failed after an attacker configured an account with single sign-on and invited real users into the setup.
- At least six Brevo accounts were used to send phishing emails.
- Trezor says the initial phishing email was sent to about 347,000 newsletter customers, and it is treating those addresses as potentially exposed.
- BitBox and CoinTracking also confirmed unauthorized newsletter activity routed through Brevo, though they reported no evidence of lost funds or exposed recovery phrases.
How Brevo’s login flaw enabled cross-account access
Brevo’s postmortem describes a pathway in which an attacker created a Brevo account, turned on single sign-on, and then invited legitimate Brevo users into the configuration. Brevo said the design should have confined access to the organization associated with the configuration, but the authorization boundary did not hold.
As a result, the attacker was able to reach every organization the invited users could access. Brevo’s write-up links the exposure directly to this breakdown in access controls, rather than to a breach of the affected organizations’ own systems.
The incident surfaced publicly after warnings from Trezor and BitBox earlier in the week, which pointed to their shared email provider and explained why the fraudulent emails appeared credible and passed ordinary authentication checks.
Phishing mechanics: what recipients were asked to do
Trezor said the phishing email—titled “Critical Security Alert: STM32 Entropy Vulnerability”—included a link to an app designed to solicit wallet backups. According to Trezor, the company disabled the domain at the DNS level within about 20 minutes. Even with the rapid takedown, Trezor reported that about 2,500 people accessed the link before it was blocked.
Trezor also emphasized the broader risk to its subscriber list. In comments provided to Cointelegraph, a Trezor spokesperson said the initial email was sent to 347,000 customers, and that all recipients were subsequently contacted about the danger.
The spokesperson added: “Until we hear more from Brevo, we are treating all roughly 347,000 newsletter addresses as known to the attacker and possibly reusable for phishing.” Trezor further stated that its Brevo account stored only opt-in newsletter email addresses and no other customer data.
Hardware wallet and crypto services respond: exposure without confirmed credential theft
BitBox told Cointelegraph that its unauthorized email was delivered through Brevo and appeared to reach its full newsletter and tutorial audience.
In its response, BitBox said Brevo held only email addresses and language preferences for it. BitBox reported no evidence of compromised company credentials, no indication that attackers downloaded data beyond the newsletter contacts, and no signs of funds being stolen or recovery phrases disclosed. Still, it said it is treating the list as potentially accessed while awaiting Brevo’s logs.
CoinTracking, meanwhile, reported separate phishing activity. The company said its Brevo account distributed an email titled “Data Breach Notice: Please refresh API Keys as soon as possible.” CoinTracking warned recipients not to click the links in the message, indicating that the main threat was credential-related phishing rather than immediate compromise of underlying systems.
Together, the responses underline a common pattern in third-party email incidents: the most immediate harm may be messaging-based, but the bigger operational concern is whether contact lists can be reused for follow-on attacks.
What Brevo disclosed—and what remains unclear
Brevo’s incident report focuses on the account-access path, but some details remain ambiguous for downstream victims. Brevo said contact exports occurred across 43 accounts and that 93 accounts showed no meaningful activity, without specifying whether those numbers overlap or how many organizations were fully affected end-to-end.
Brevo also did not provide, in the disclosed summary, a precise mapping from the six sending accounts to the different affected crypto companies’ audiences. Cointelegraph attempted to request additional information from Brevo but received no response before publication.
For investors, traders, and builders, the relevance extends beyond the immediate phishing harm: reputable crypto firms rely on email service providers to communicate security alerts, product updates, and documentation. When those communications channels can be abused—especially when phishing content looks authentic—users may face repeated attempts that target them again using addresses already in the attacker’s possession.
Going forward, recipients of such newsletters should be cautious about any unexpected security prompts, verify warnings through official channels, and avoid entering sensitive data into links from unsolicited messages. The core uncertainty now is how thoroughly Brevo’s investigation identifies which organizations’ contacts were exported versus merely accessed, and whether the attacker obtained broader metadata that could support additional phishing campaigns.
Crypto firms and their customers should watch for follow-on updates from Brevo’s incident findings—particularly any clarification on which accounts were used for exports and whether any categories of access overlap—while continuing to educate users to treat “urgent security alerts” sent via newsletter channels as untrusted until verified independently.
This article was originally published as Brevo Login Flaw Linked to Phishing Attacks on 347K Trezor Users on Crypto Breaking News – your trusted source for crypto news, Bitcoin news, and blockchain updates.