Skip to main content

Brevo Login Flaw Linked to Phishing Attacks on 347K Trezor Users



Brevo, an email delivery platform used across the crypto industry, disclosed that an attacker leveraged a login-system weakness to gain access to multiple client accounts. The incident allowed phishing messages to be sent to a combined audience of roughly 347,000 Trezor newsletter subscribers, with additional campaigns also reaching audiences tied to BitBox and CoinTracking.



In a Thursday postmortem, Brevo said the attacker used six accounts to send phishing emails. It also reported that contacts were exported from 43 accounts, while 93 accounts showed no meaningful activity—though Brevo did not clarify whether those categories overlap. Brevo added that the access-control boundary that should have limited the attacker’s reach to a single organization failed.



Key takeaways



  • Brevo reported that an authorization boundary failed after an attacker configured an account with single sign-on and invited real users into the setup.

  • At least six Brevo accounts were used to send phishing emails.

  • Trezor says the initial phishing email was sent to about 347,000 newsletter customers, and it is treating those addresses as potentially exposed.

  • BitBox and CoinTracking also confirmed unauthorized newsletter activity routed through Brevo, though they reported no evidence of lost funds or exposed recovery phrases.



How Brevo’s login flaw enabled cross-account access


Brevo’s postmortem describes a pathway in which an attacker created a Brevo account, turned on single sign-on, and then invited legitimate Brevo users into the configuration. Brevo said the design should have confined access to the organization associated with the configuration, but the authorization boundary did not hold.



As a result, the attacker was able to reach every organization the invited users could access. Brevo’s write-up links the exposure directly to this breakdown in access controls, rather than to a breach of the affected organizations’ own systems.



The incident surfaced publicly after warnings from Trezor and BitBox earlier in the week, which pointed to their shared email provider and explained why the fraudulent emails appeared credible and passed ordinary authentication checks.



Phishing mechanics: what recipients were asked to do


Trezor said the phishing email—titled “Critical Security Alert: STM32 Entropy Vulnerability”—included a link to an app designed to solicit wallet backups. According to Trezor, the company disabled the domain at the DNS level within about 20 minutes. Even with the rapid takedown, Trezor reported that about 2,500 people accessed the link before it was blocked.



Trezor also emphasized the broader risk to its subscriber list. In comments provided to Cointelegraph, a Trezor spokesperson said the initial email was sent to 347,000 customers, and that all recipients were subsequently contacted about the danger.



The spokesperson added: “Until we hear more from Brevo, we are treating all roughly 347,000 newsletter addresses as known to the attacker and possibly reusable for phishing.” Trezor further stated that its Brevo account stored only opt-in newsletter email addresses and no other customer data.



Hardware wallet and crypto services respond: exposure without confirmed credential theft


BitBox told Cointelegraph that its unauthorized email was delivered through Brevo and appeared to reach its full newsletter and tutorial audience.



In its response, BitBox said Brevo held only email addresses and language preferences for it. BitBox reported no evidence of compromised company credentials, no indication that attackers downloaded data beyond the newsletter contacts, and no signs of funds being stolen or recovery phrases disclosed. Still, it said it is treating the list as potentially accessed while awaiting Brevo’s logs.



CoinTracking, meanwhile, reported separate phishing activity. The company said its Brevo account distributed an email titled “Data Breach Notice: Please refresh API Keys as soon as possible.” CoinTracking warned recipients not to click the links in the message, indicating that the main threat was credential-related phishing rather than immediate compromise of underlying systems.



Together, the responses underline a common pattern in third-party email incidents: the most immediate harm may be messaging-based, but the bigger operational concern is whether contact lists can be reused for follow-on attacks.



What Brevo disclosed—and what remains unclear


Brevo’s incident report focuses on the account-access path, but some details remain ambiguous for downstream victims. Brevo said contact exports occurred across 43 accounts and that 93 accounts showed no meaningful activity, without specifying whether those numbers overlap or how many organizations were fully affected end-to-end.



Brevo also did not provide, in the disclosed summary, a precise mapping from the six sending accounts to the different affected crypto companies’ audiences. Cointelegraph attempted to request additional information from Brevo but received no response before publication.



For investors, traders, and builders, the relevance extends beyond the immediate phishing harm: reputable crypto firms rely on email service providers to communicate security alerts, product updates, and documentation. When those communications channels can be abused—especially when phishing content looks authentic—users may face repeated attempts that target them again using addresses already in the attacker’s possession.



Going forward, recipients of such newsletters should be cautious about any unexpected security prompts, verify warnings through official channels, and avoid entering sensitive data into links from unsolicited messages. The core uncertainty now is how thoroughly Brevo’s investigation identifies which organizations’ contacts were exported versus merely accessed, and whether the attacker obtained broader metadata that could support additional phishing campaigns.



Crypto firms and their customers should watch for follow-on updates from Brevo’s incident findings—particularly any clarification on which accounts were used for exports and whether any categories of access overlap—while continuing to educate users to treat “urgent security alerts” sent via newsletter channels as untrusted until verified independently.



https://www.cryptobreaking.com/brevo-login-flaw-linked-to/?utm_source=blogger%20&utm_medium=social_auto&utm_campaign=Brevo%20Login%20Flaw%20Linked%20to%20Phishing%20Attacks%20on%20347K%20Trezor%20Users%20

Comments

Popular posts from this blog

Mastercard Launches AI Agent Pay System With Ripple and Solana Help

Mastercard has launched Agent Pay for Machines, a payments system built for autonomous software agents. The service allows AI agents to send and receive payments without direct human action. It brings Ripple, Coinbase, and Solana Foundation into Mastercard’s push for automated digital commerce. Ripple Brings XRPL and RLUSD to Mastercard’s Agent Pay System Mastercard introduced Agent Pay for Machines on June 10 as a tool for machine-led payments. The system targets high-volume and low-value transactions across business and consumer use cases. It also supports automated settlement between software agents and connected machines. Ripple will support the system through the XRP Ledger and its RLUSD stablecoin. The company said that settlement will become more important as automated commerce grows. It also sees blockchain rails as useful for fast and rule-based payments. RippleX senior vice president Markus Infanger said XRPL and RLUSD support enterprise-grade agent payments. He said the tool...

Top Cryptocurrencies to Watch: BTC, ETH, BNB, XRP, Solana, Dogecoin & More

Market Analysis and Price Predictions for Key Cryptocurrencies Recent market dynamics reveal a cautious sentiment across the cryptocurrency landscape, with Bitcoin struggling to maintain levels above $90,000 and many major altcoins facing downward pressure. Indicators point toward reduced participation from both institutional and retail investors, raising concerns about a potential consolidation phase after notable gains earlier in the year. Bitcoin has fallen below $87,000, reflecting waning demand at higher price points. Institutional fund flows into BTC and ETH ETFs have turned negative, indicating a period of subdued market activity. Active addresses and Binance deposit/withdrawal activities are at annual lows, suggesting market indecision. Most leading altcoins are approaching support levels, with some poised for potential breakdowns. Tickers mentioned: Bitcoin, Ethereum, Binance Coin, XRP, Solana, Dogecoin, Cardano, Bitcoin Cash, Chainlink, Hyperliquid Sentiment: Neutral to Sli...

Coinbase's x402 launches AI agents app store for payments

Coinbase-backed x402 has unveiled Agentic.market, a dedicated marketplace aimed at increasing the usefulness of AI agents by aggregating thousands of apps and services that agents can access without any API keys. The rollout positions the platform as a central hub for agents to discover, evaluate, and deploy capabilities across a standardized payments layer. Coinbase product lead Nick Prince described Agentic.market in a video posted on X as a storefront for discovering, comparing, and using x402 services. The marketplace is designed to give both humans and their AI agents access to a wide range of tools—from data feeds to consumer apps—without the friction of managing API credentials. A storefront for discovering, comparing, and using x402 services. Thousands of services. Zero API keys. Powered by x402. Prince added that the market offers a web interface for humans to browse and assess services, alongside a programming layer that lets AI agents autonomously search, filter, and integra...