Key Takeaways
- An authentication vulnerability in Brevo’s email service enabled unauthorized access to 138 customer accounts
- Approximately 347,000 Trezor newsletter recipients were sent a phishing message with a fraudulent link
- Hardware wallet providers BitBox and tax platform CoinTracking also experienced unauthorized access via their Brevo accounts
- Roughly 2,500 individuals clicked the malicious link before Trezor shut down the fraudulent domain in under 20 minutes
- According to Trezor, no user credentials, wallet information, or core product infrastructure was compromised
An authentication weakness in Brevo, a widely-used email marketing service, enabled an unauthorized party to compromise 138 customer accounts and distribute phishing messages to hundreds of thousands of cryptocurrency holders.
The security incident impacted Trezor, BitBox, and CoinTracking—three prominent cryptocurrency companies that rely on Brevo for managing their subscriber communications.
Details of the Security Exploit
The threat actor established a Brevo account, activated single sign-on functionality, and sent invitations to genuine Brevo account holders to join their workspace. A critical authorization boundary defect subsequently provided the attacker with access to all organizations associated with those invited accounts.
Brevo’s subsequent investigation revealed that six compromised accounts were utilized to distribute phishing messages, 43 accounts had subscriber data extracted, and 93 accounts displayed no significant unauthorized activity.
The campaign was carefully designed to circumvent standard email verification protocols, causing the fraudulent messages to appear legitimate to unsuspecting recipients.
The Phishing Campaign Targeting Trezor Users
All 347,000 individuals subscribed to Trezor’s newsletter received a fraudulent message with the headline “Critical Security Alert: STM32 Entropy Vulnerability.”
The message directed recipients to a counterfeit application designed to capture wallet recovery phrases, which would grant attackers complete control over victims’ cryptocurrency holdings.
Trezor’s security team deactivated the malicious domain through DNS-level intervention within 20 minutes of identifying the threat. However, approximately 2,500 users had already accessed the fraudulent link prior to its removal.
Trezor emphasized that its Brevo account contained exclusively opt-in newsletter email addresses. No authentication credentials, private keys, or additional personal details were stored on the platform.
The hardware wallet manufacturer is now considering all 347,000 affected email addresses as potentially exposed and vulnerable to subsequent phishing operations.
Impact on BitBox and CoinTracking
BitBox reported that the malicious email successfully reached subscribers on both its newsletter and educational tutorial distribution lists via Brevo. The company’s investigation found no indication of contact database downloads, stolen funds, or compromised seed phrases.
BitBox verified that its Brevo database contained solely email addresses and user language preference settings.
CoinTracking’s compromised Brevo account was exploited to distribute a message with the subject line “Data Breach Notice: Please refresh API Keys as soon as possible.” The platform immediately instructed users to disregard and avoid interacting with any links contained in that communication.
Trezor has since terminated its Brevo service agreement and implemented prominent security warnings throughout its website, mobile application, and customer support platforms.
If you submitted your recovery phrase after accessing the malicious link, Trezor strongly recommends transferring all assets to a newly generated wallet without delay. Simply clicking the link without providing sensitive information does not compromise your funds.
Trezor has announced it is conducting a comprehensive audit of its third-party service providers and strengthening security protocols across all vendor relationships.


