A single login flaw in Brevo exposed 347,000 Trezor users to phishing

About 2,500 people clicked a malicious link before Trezor could shut it down. That’s the number that should make any crypto user uncomfortable, but the bigger story here is how the attack worked and how many people are still exposed.

According to Cointelegraph, an attacker exploited a flaw in email platform Brevo’s login system to access 138 client accounts. The method was methodical: the attacker created a Brevo account, enabled single sign-on, then invited legitimate Brevo users into that configuration. Brevo’s system was supposed to contain access within a single organization. It didn’t. An authorization boundary failed and the attacker gained access to every organization those invited users could reach. That’s a serious architectural failure, not a minor bug.

Six of the compromised accounts were used to send phishing emails. Contacts were exported from 43 accounts. The remaining 93 showed no meaningful activity, though Brevo didn’t clarify whether these categories overlapped. That lack of clarity is its own problem.

Trezor was the most visibly affected. The phishing message, titled “Critical Security Alert: STM32 Entropy Vulnerability,” pointed users to a fake app requesting their wallet backup phrases. Trezor killed the domain at the DNS level within 20 minutes. But by then, roughly 2,500 people had already clicked. The company told Cointelegraph the email reached 347,000 newsletter subscribers, and its position is blunt: it’s treating every one of those addresses as known to the attacker and potentially reusable for future phishing. That’s the right call. It’s also a sign of how serious this is.

BitBox confirmed its newsletter and tutorial list was also hit through the same Brevo account. CoinTracking, a crypto portfolio and tax-reporting platform, said its Brevo account sent out an email titled “Data Breach Notice: Please refresh API Keys as soon as possible” and warned its own users not to follow the links in it. So three separate crypto companies, all using the same email service provider, all caught in the same attack.

What makes this particularly damaging is that the phishing emails passed standard authentication checks. They looked real because they came from real sending infrastructure. Users had no obvious technical signal that something was wrong.

This attack fits a pattern the security community has been warning about for years. Third-party email platforms hold enormous amounts of user data, and their security posture directly affects every company that relies on them. Crypto firms are high-value targets. Pairing that with a shared, flawed email provider is a risk that clearly wasn’t treated seriously enough.

  • Trezor: 347,000 newsletter addresses potentially known to attacker
  • BitBox: full newsletter and tutorial list likely reached
  • CoinTracking: distributed fake “data breach” notice through compromised account
  • Brevo: 138 accounts accessed, 6 used for phishing, 43 had contacts exported

Brevo had not responded to Cointelegraph’s request for comment at the time of publication. That silence, following a breach of this scale, is not a great look for a platform that companies trusted with their customer data.