An attacker exploited a flaw in email platform Brevo's login system to access 138 client accounts and distribute phishing emails to users of three cryptocurrency companies: hardware wallet provider Trezor, wallet maker BitBox, and crypto portfolio platform CoinTracking.
According to Brevo's Thursday postmortem, the attacker created a Brevo account, enabled single sign-on, and invited legitimate Brevo users into the configuration. The platform said access should have been restricted to that organization, but an authorization boundary failure granted the attacker access to every organization the invited users could reach. Six accounts were used to send phishing emails, contacts were exported from 43 accounts, and 93 accounts showed no meaningful activity.
Attack Details and Impact
Trezor reported that the phishing email, titled "Critical Security Alert: STM32 Entropy Vulnerability," contained a link to an app requesting users' wallet backups. The company disabled the domain at the DNS level within 20 minutes, but approximately 2,500 people accessed the link before the takedown. Trezor's Brevo account stored only opt-in newsletter email addresses and no other customer data.
A Trezor spokesperson told Cointelegraph that the initial email was sent to 347,000 customers, all of whom were subsequently contacted about the risk. The company is treating all newsletter addresses as known to the attacker and possibly reusable for phishing.
BitBox said its unauthorized email was sent through Brevo to its full newsletter and tutorial list. The company found no evidence of compromised credentials, downloaded contacts, lost funds, or disclosed recovery phrases, but is treating the email list as potentially accessed pending Brevo's logs. BitBox's Brevo account contained only email addresses and language preferences.
CoinTracking's Brevo account distributed an email titled "Data Breach Notice: Please refresh API Keys as soon as possible." The company warned recipients not to follow the email's links.


