Community Trust ScoreVerified
A login vulnerability in Brevo’s system let an attacker blast phishing emails to 347,000 Trezor subscribers. It didn’t stop there. BitBox and CoinTracking got hit too, all through the same broken door.
The attacker’s method was pretty simple, which makes it worse. They created a Brevo account, then invited legitimate users into it. A boundary error in Brevo’s single sign-on system handed over far more access than it should have — basically opening the door to 138 accounts across multiple clients. Six of those accounts were actively used to fire off phishing emails. Data was exported from 43 accounts. Whether those two groups overlapped, Brevo didn’t say. Still hasn’t.
The emails got through clean.
Because the messages traveled through Brevo’s own infrastructure, they passed standard authentication checks without raising flags. Recipients had no obvious reason to distrust them. The phishing email targeting Trezor users carried the subject line “Critical Security Alert: STM32 Entropy Vulnerability” — the kind of technical-sounding alarm that makes hardware wallet users panic and click fast. That’s exactly what happened. Trezor killed the malicious link within 20 minutes, but 2,500 users had already accessed it by then.
Three Platforms, One Broken System
Trezor moved fast. The company sent warnings to affected subscribers and confirmed that only email addresses were exposed — no additional customer data, no seed phrases, no funds directly at risk from the breach itself. The risk, as Trezor framed it, is what comes next. With 347,000 email addresses now in an attacker’s hands, future phishing attempts are pretty much guaranteed. Trezor said it’s treating the entire subscriber list as compromised until Brevo gives clearer answers.
BitBox confirmed the same thing. Its full newsletter and tutorial list went through Brevo, which means every address on it was potentially exposed. The company reported no compromised credentials and no lost funds, but it’s waiting on detailed logs from Brevo before drawing firmer conclusions. BitBox said the breach involved email addresses and language preferences — nothing deeper, as far as it can tell right now.
CoinTracking’s situation was slightly different in tone. The platform issued a warning about an email with the subject “Data Breach Notice: Please refresh API Keys as soon as possible.” That’s a classic social engineering move — create urgency, demand immediate action, slip in a malicious link. CoinTracking told users not to click anything in the email and said it’s still assessing the full impact.
Brevo’s Authorization Failure
The core problem here is an authorization boundary that didn’t hold. Brevo’s system failed to keep one client’s access separate from another’s. When the attacker set up their own Brevo account and started inviting users, the platform’s permission model apparently didn’t catch it. That misstep gave unauthorized access across multiple organizations — not just one.
It’s murky exactly how that boundary broke down. Brevo acknowledged the breach but hasn’t put out a detailed technical explanation. No clarity on what the authorization model was supposed to do, no word on whether similar flaws exist elsewhere in the system. Affected companies are basically waiting.
That wait is uncomfortable. Email marketing platforms sit at a weird intersection — they hold contact lists for hundreds of clients, process sensitive communications, and act as a trusted middleman between companies and their users. When that trust breaks, it doesn’t just affect one organization. It cascades. Trezor, BitBox, and CoinTracking found that out the hard way, all at once, from a single compromised infrastructure layer.
Crypto users are already primed targets for phishing. Hardware wallet holders especially — attackers know they’re likely holding real assets and that a convincing enough scare about a “vulnerability” can make even careful people act without thinking. The STM32 entropy framing in the Trezor email was specific enough to sound credible. That’s not accidental.
And the 2,500 users who clicked the link before Trezor disabled it? Unclear what happened to them specifically. The company said no additional customer data was involved in the breach itself, but what users may have entered on the other end of that link — that’s a separate question nobody’s answered yet.
Brevo hasn’t responded to follow-up queries on specifics. BitBox is still waiting on logs. CoinTracking is still assessing. Three platforms, one broken system, and a lot of unanswered questions sitting with a third-party vendor that’s gone quiet.
Frequently Asked Questions
How did the attacker gain access to Trezor’s subscriber list through Brevo?
The attacker created a Brevo account and exploited a boundary error in the platform’s single sign-on system, gaining unauthorized access to 138 accounts and ultimately sending phishing emails to all 347,000 Trezor subscribers.
Were any funds or passwords stolen in the Trezor-Brevo phishing breach?
Trezor and BitBox both said no credentials or funds were directly compromised by the breach itself, though 2,500 Trezor users clicked the malicious link before it was disabled within 20 minutes.
Why It Matters
The Brevo SSO flaw highlights the ongoing vulnerabilities in digital security systems, particularly in the cryptocurrency sector, where user trust is paramount. As phishing attacks continue to target cryptocurrency enthusiasts, incidents like this can undermine confidence in platforms and services, potentially leading to a decline in user adoption and heightened regulatory scrutiny. Ensuring robust security measures is crucial for maintaining the integrity of the crypto ecosystem, particularly as it faces increasing threats from malicious actors.





