Market desk Bitcoin Ethereum Altcoins DeFi Stablecoins Markets & Trading

Brevo Login Flaw Enabled Phishing Attack on Trezor, BitBox, and CoinTracking Users

An attacker exploited a security flaw in email platform Brevo to compromise 138 client accounts and send phishing emails to approximately 347,000 Trezor newsletter subscribers, with similar fraudulent messages reaching BitBox and CoinTracking users.
3 hours ago 8 views
Brevo Login Flaw Enabled Phishing Attack on Trezor, BitBox, and CoinTracking Users

An attacker exploited a flaw in email platform Brevo's login system to access 138 client accounts and distribute phishing emails to users of three cryptocurrency companies: hardware wallet provider Trezor, wallet maker BitBox, and crypto portfolio platform CoinTracking.

According to Brevo's Thursday postmortem, the attacker created a Brevo account, enabled single sign-on, and invited legitimate Brevo users into the configuration. The platform said access should have been restricted to that organization, but an authorization boundary failure granted the attacker access to every organization the invited users could reach. Six accounts were used to send phishing emails, contacts were exported from 43 accounts, and 93 accounts showed no meaningful activity.

Attack Details and Impact

Trezor reported that the phishing email, titled "Critical Security Alert: STM32 Entropy Vulnerability," contained a link to an app requesting users' wallet backups. The company disabled the domain at the DNS level within 20 minutes, but approximately 2,500 people accessed the link before the takedown. Trezor's Brevo account stored only opt-in newsletter email addresses and no other customer data.

A Trezor spokesperson told Cointelegraph that the initial email was sent to 347,000 customers, all of whom were subsequently contacted about the risk. The company is treating all newsletter addresses as known to the attacker and possibly reusable for phishing.

BitBox said its unauthorized email was sent through Brevo to its full newsletter and tutorial list. The company found no evidence of compromised credentials, downloaded contacts, lost funds, or disclosed recovery phrases, but is treating the email list as potentially accessed pending Brevo's logs. BitBox's Brevo account contained only email addresses and language preferences.

CoinTracking's Brevo account distributed an email titled "Data Breach Notice: Please refresh API Keys as soon as possible." The company warned recipients not to follow the email's links.

Market snapshot

Top cryptocurrency prices

Explore all prices
BitcoinBTC $77,302.00-0.87% EthereumETH $2,468.88+0.13% Tether USDUSDT $1.0000+0.01% BNBBNB $714.54-0.23% XRPXRP $1.36-1.72% USDCUSDC $1.000.00% SolanaSOL $99.84-1.07% TRONTRX $0.3389-0.15% HyperliquidHYPE $80.13-3.32% ZcashZEC $1,112.49-8.31%
Prices by Coinranking. Informational only.