Brevo login flaw enabled phishing email targeting 347K Trezor subscribers
A flaw in email platform Brevo's login system allowed an attacker to access 138 client accounts, leading to phishing emails targeting 347,000 Trezor newsletter subscribers, as well as users of BitBox and CoinTracking.
Intelligence analysis by Gemini 2.5 Flash

The security vulnerability in Brevo's single sign-on system enabled an attacker to bypass authorization boundaries, gaining access to client accounts of major crypto firms. This breach facilitated the distribution of highly convincing phishing emails, prompting urgent warnings from Trezor, BitBox, and CoinTracking to their respective user bases.
Imagine a special club where you get emails about your favorite toys. Someone found a secret trick to get into the club's email system, even though they weren't supposed to. They then sent fake emails that looked real, pretending to be from the toy companies, asking kids to give away their secret toy codes. Even though the toy companies quickly stopped the fake emails, many kids' email addresses are now known to the trickster, so everyone needs to be extra careful about what they click.
Analysis
The recent security breach involving Brevo, a widely used email marketing platform, underscores a significant vulnerability within the broader digital infrastructure that supports cryptocurrency services. An attacker exploited a flaw in Brevo's login system, specifically related to its single sign-on (SSO) functionality, to gain unauthorized access to 138 client accounts. This was not a direct attack on the crypto firms themselves, but rather a compromise of a shared third-party vendor, illustrating how interconnected digital services can create cascading security risks.
Brevo's Authorization Boundary
The core of the breach lay in a critical authorization boundary failure within Brevo's system. The attacker initially created their own Brevo account, enabled single sign-on, and then invited legitimate Brevo users into their configuration. While access should have been confined to the attacker's organization, the system failed to enforce this boundary, granting the attacker access to every organization that the invited users could reach. This systemic flaw allowed the attacker to export contact lists and send phishing emails from compromised accounts, making the fraudulent messages appear legitimate to recipients due to their origin from trusted senders.
Trezor's Immediate Response
Trezor, a prominent hardware wallet manufacturer, was significantly impacted, with approximately 347,000 of its newsletter subscribers receiving a phishing email titled “Critical Security Alert: STM32 Entropy Vulnerability.” This email contained a link designed to trick users into revealing their wallet backups. Trezor acted swiftly, disabling the malicious domain at the DNS level within 20 minutes of detection. Despite this rapid response, about 2,500 individuals accessed the link before it was taken down. Trezor confirmed that its Brevo account only stored opt-in newsletter email addresses, not sensitive customer data, but is treating all 347,000 addresses as potentially compromised for future phishing attempts.
BitBox and CoinTracking Affected
Beyond Trezor, other notable crypto entities, BitBox and CoinTracking, also fell victim to the Brevo breach. BitBox, another hardware wallet provider, reported that an unauthorized email was sent through its Brevo account, reaching its full newsletter and tutorial list. Similar to Trezor, BitBox's Brevo account only held email addresses and language preferences, with no evidence of compromised company credentials or lost funds. CoinTracking, a crypto portfolio tracking and tax-reporting platform, also had its Brevo account used to distribute a phishing email titled “Data Breach Notice: Please refresh API Keys as soon as possible,” urging recipients not to click on any links. These incidents collectively highlight the widespread impact a single vulnerability in a shared service can have across the crypto industry.
Key points
- A flaw in Brevo's login system allowed an attacker to access 138 client accounts, including those of Trezor, BitBox, and CoinTracking.
- The breach enabled the distribution of phishing emails to approximately 347,000 Trezor newsletter subscribers.
- Trezor quickly disabled the malicious domain, but about 2,500 users accessed the phishing link before it was taken down.
- Affected companies confirmed that only email addresses and language preferences were stored on Brevo, not sensitive customer data or wallet information.
- All affected firms have warned their users to be extremely cautious of suspicious emails and to never share recovery phrases or wallet backups.
The rapid response from affected companies like Trezor, which disabled the phishing domain within minutes and immediately warned users, demonstrates effective incident management. The fact that only email addresses were exposed, not sensitive wallet data or funds, limits the direct financial damage from this specific breach.
The exposure of 347,000 Trezor subscriber email addresses, along with those from BitBox and CoinTracking, creates a large pool of targets for future, more sophisticated phishing attacks. Users must remain highly vigilant, as these email addresses are now known to attackers and could be used in subsequent attempts to compromise crypto assets.


