Brevo Security Flaw Triggers Crypto Phishing Campaign
A security flaw in email platform Brevo allowed an attacker to access hundreds of client accounts and distribute phishing emails through trusted crypto brands, putting approximately 347,000 Trezor newsletter subscribers at risk.
The incident affected several cryptocurrency companies, including hardware wallet manufacturer Trezor, hardware wallet provider BitBox, and crypto portfolio and tax-reporting platform CoinTracking.
The incident highlights a growing security risk for crypto users: attackers do not always need to compromise a wallet provider directly when they can exploit a trusted third-party service used to communicate with customers.
How the Brevo Login Flaw Worked
According to Brevo's postmortem, the attacker created a Brevo account, enabled single sign-on and invited legitimate Brevo users into the organization.
The access was supposed to remain restricted to that organization. However, an authorization-boundary failure allowed the invited users to gain access to organizations they were already authorized to reach.
Brevo said the incident involved 138 client accounts. Six accounts were used to send phishing emails, while contacts were exported from 43 accounts. Another 93 accounts showed no meaningful activity.
The company did not clarify whether those categories overlapped.
Trezor Phishing Email Reached 347,000 Subscribers
The most significant known impact involved Trezor.
The attacker distributed an email titled “Critical Security Alert: STM32 Entropy Vulnerability”, designed to appear like an urgent hardware-wallet security notification.
The message directed recipients to an application that requested their wallet backups — information that could potentially give an attacker control over cryptocurrency holdings.
Trezor said it disabled the malicious domain at the DNS level within approximately 20 minutes of identifying the attack.
However, around 2,500 people accessed the phishing link before the domain was taken down.
Trezor subsequently contacted its approximately 347,000 newsletter subscribers about the incident.
Why the Emails Appeared Legitimate
The campaign was particularly concerning because the messages were distributed through Brevo's legitimate infrastructure.
That meant recipients could see emails that appeared to originate from a trusted company and potentially pass normal email authentication checks.
This is an important distinction from conventional phishing campaigns sent from newly created or suspicious domains.
An attacker compromising a trusted communications provider can effectively borrow the reputation of the affected company, making social engineering attempts considerably more convincing.
BitBox and CoinTracking Also Affected
Trezor was not the only crypto company impacted.
BitBox said an unauthorized email was distributed through its Brevo account and appeared to have reached its full newsletter and tutorial mailing list.
The company said Brevo stored email addresses and language preferences for its users. BitBox reported no evidence that company credentials, recovery phrases or customer funds had been compromised, but it is treating the mailing list as potentially exposed while awaiting additional logs.
CoinTracking also reported that its Brevo account was used to distribute an unauthorized email.
The incidents demonstrate how a single third-party service can create a broad attack surface across multiple cryptocurrency companies.
What Crypto Users Should Do
Users who received suspicious messages from Trezor, BitBox, CoinTracking or other crypto companies should treat unexpected security emails with extreme caution.
Never Enter a Wallet Backup From an Email Link
Legitimate security communications should not require users to provide their recovery phrase or wallet backup through an email-linked application.
A recovery phrase should never be entered into a website or app simply because an email claims that a wallet is at risk.
Verify Through Official Channels
Instead of clicking links inside an unexpected security email, users should manually open the company's official website or wallet application and check for announcements.
Users should also inspect the destination domain carefully and avoid connecting a wallet or signing transactions after following an unsolicited security alert.
Third-Party Providers Are a Major Security Consideration
The Brevo incident demonstrates that crypto security extends beyond blockchain infrastructure and wallet software.
Exchanges, wallet providers and crypto applications frequently depend on third-party services for email marketing, analytics, customer support and authentication.
A vulnerability in one of those providers can give attackers access to trusted communication channels even when the underlying crypto company's own systems remain secure.
For users, that means an authentic-looking email is not automatically proof that its contents are safe.
Bottom Line
The Brevo incident exposed approximately 347,000 Trezor newsletter subscribers to a sophisticated phishing campaign and affected communications for other crypto companies including BitBox and CoinTracking.
Although there is no indication from the reported incident that Trezor's wallet infrastructure itself was compromised, the attack shows how third-party service providers can become an indirect entry point for cryptocurrency theft.
For Bitcoin and crypto users, the safest approach remains simple: never share a recovery phrase through an email link, verify security alerts through official channels, and treat unexpected wallet-related messages as potentially malicious.