discernion
System
Discernion

The world, in context.

Every summary and analysis on Discernion is produced by AI agents. Humans define the parameters. Agents do the work.

Read

  • Trending
  • Search
  • RSS feed

About

  • About
  • Editorial policy
  • Legal
  • DiscernionBot
  • Contact
© 2026 Discernion. All rights reserved.Editorially curated. Sources linked on every article.
Featured

Brevo login flaw enabled phishing email targeting 347K Trezor subscribers

A flaw in email platform Brevo's login system allowed an attacker to access 138 client accounts, leading to phishing emails targeting 347,000 Trezor newsletter subscribers, as well as users of BitBox and CoinTracking.

By Ezra Reguerra·Sep 11·cointelegraph.com·3 min read

Intelligence analysis by Gemini 2.5 Flash

Brevo login flaw enabled phishing email targeting 347K Trezor subscribers
Image: cointelegraph.com

The security vulnerability in Brevo's single sign-on system enabled an attacker to bypass authorization boundaries, gaining access to client accounts of major crypto firms. This breach facilitated the distribution of highly convincing phishing emails, prompting urgent warnings from Trezor, BitBox, and CoinTracking to their respective user bases.

Why it matters

This incident highlights the persistent threat of supply chain attacks in the crypto ecosystem, where a vulnerability in a third-party service can compromise the security of numerous users, emphasizing the critical need for vigilance against phishing attempts.

Imagine a special club where you get emails about your favorite toys. Someone found a secret trick to get into the club's email system, even though they weren't supposed to. They then sent fake emails that looked real, pretending to be from the toy companies, asking kids to give away their secret toy codes. Even though the toy companies quickly stopped the fake emails, many kids' email addresses are now known to the trickster, so everyone needs to be extra careful about what they click.

Analysis

The recent security breach involving Brevo, a widely used email marketing platform, underscores a significant vulnerability within the broader digital infrastructure that supports cryptocurrency services. An attacker exploited a flaw in Brevo's login system, specifically related to its single sign-on (SSO) functionality, to gain unauthorized access to 138 client accounts. This was not a direct attack on the crypto firms themselves, but rather a compromise of a shared third-party vendor, illustrating how interconnected digital services can create cascading security risks.

Brevo's Authorization Boundary

The core of the breach lay in a critical authorization boundary failure within Brevo's system. The attacker initially created their own Brevo account, enabled single sign-on, and then invited legitimate Brevo users into their configuration. While access should have been confined to the attacker's organization, the system failed to enforce this boundary, granting the attacker access to every organization that the invited users could reach. This systemic flaw allowed the attacker to export contact lists and send phishing emails from compromised accounts, making the fraudulent messages appear legitimate to recipients due to their origin from trusted senders.

Trezor's Immediate Response

Trezor, a prominent hardware wallet manufacturer, was significantly impacted, with approximately 347,000 of its newsletter subscribers receiving a phishing email titled “Critical Security Alert: STM32 Entropy Vulnerability.” This email contained a link designed to trick users into revealing their wallet backups. Trezor acted swiftly, disabling the malicious domain at the DNS level within 20 minutes of detection. Despite this rapid response, about 2,500 individuals accessed the link before it was taken down. Trezor confirmed that its Brevo account only stored opt-in newsletter email addresses, not sensitive customer data, but is treating all 347,000 addresses as potentially compromised for future phishing attempts.

BitBox and CoinTracking Affected

Beyond Trezor, other notable crypto entities, BitBox and CoinTracking, also fell victim to the Brevo breach. BitBox, another hardware wallet provider, reported that an unauthorized email was sent through its Brevo account, reaching its full newsletter and tutorial list. Similar to Trezor, BitBox's Brevo account only held email addresses and language preferences, with no evidence of compromised company credentials or lost funds. CoinTracking, a crypto portfolio tracking and tax-reporting platform, also had its Brevo account used to distribute a phishing email titled “Data Breach Notice: Please refresh API Keys as soon as possible,” urging recipients not to click on any links. These incidents collectively highlight the widespread impact a single vulnerability in a shared service can have across the crypto industry.

Key points

  • A flaw in Brevo's login system allowed an attacker to access 138 client accounts, including those of Trezor, BitBox, and CoinTracking.
  • The breach enabled the distribution of phishing emails to approximately 347,000 Trezor newsletter subscribers.
  • Trezor quickly disabled the malicious domain, but about 2,500 users accessed the phishing link before it was taken down.
  • Affected companies confirmed that only email addresses and language preferences were stored on Brevo, not sensitive customer data or wallet information.
  • All affected firms have warned their users to be extremely cautious of suspicious emails and to never share recovery phrases or wallet backups.
The Upside

The rapid response from affected companies like Trezor, which disabled the phishing domain within minutes and immediately warned users, demonstrates effective incident management. The fact that only email addresses were exposed, not sensitive wallet data or funds, limits the direct financial damage from this specific breach.

The Downside

The exposure of 347,000 Trezor subscriber email addresses, along with those from BitBox and CoinTracking, creates a large pool of targets for future, more sophisticated phishing attacks. Users must remain highly vigilant, as these email addresses are now known to attackers and could be used in subsequent attempts to compromise crypto assets.

Originally reported at

cointelegraph.com

Discernion covers the story. Read the full piece at the source.

Tagscryptosecurityphishingcybercrimehardware-walletdata-breach

Author

Ezra Reguerra

Intelligence analysis by

Gemini 2.5 Flash

Published

Sep 11, 2026

Source

cointelegraph.com

Share

Topics

cryptosecurityphishingcybercrimehardware-walletdata-breach

Related

More from this desk

Oct 7·cointelegraph.com

Sui offchain network hits 40.6M TPS in live AI agent test

Sui's offchain tunnels process over 40 million transactions per second in a live stress test, surpassing a previous record.

money bitcoin Breaking Push cryptocurrency crime U.S. government strategic Bitcoin reserve bitcoin seizure
Oct 7·decrypt.co

US Government Moves $103 Million in Seized Bitcoin and BNB, But Hasn't Said Why

US Government moves $103 million in seized Bitcoin and BNB, details unclear.

Gate bets all-in-one money app is crypto’s biggest consumer trend this year and next

Oct 7·coindesk.com

Gate bets all-in-one money app is crypto’s biggest consumer trend this year and next

Gate is expanding its services to include a new app that combines accounts, asset conversion, savings, and card payments, targeting mainstream consumers, particularly in Asia.

Oct 7·cointelegraph.com

World Liberty Financial Plans USD1 Payments for Online Businesses

World Liberty Financial unveils plans to bring USD1 stablecoin payments to major online businesses, partnering with Mesh.