A significant security flaw in email marketing platform Brevo has exposed approximately 347,000 Trezor newsletter subscribers to a phishing attack, raising alarms across the cryptocurrency community. The breach allowed an attacker to access 138 client accounts and send out malicious emails impersonating well-known crypto firms, including CoinTracking and BitBox.
According to reports, the attacker successfully created a Brevo account and enabled single sign-on features, inviting legitimate users to join. This authorization boundary failure provided the attacker with extensive access to the networks of those accounts, effectively bypassing standard email authentication checks. The result was a wave of phishing emails that appeared genuine to recipients, creating a false sense of security.
Among those affected, Trezor’s 347,000 newsletter subscribers received an alarming email with the subject line “Critical Security Alert: STM32 Entropy Vulnerability.” This email contained a link to a fraudulent application that prompted users to enter their wallet backup details, potentially granting the attacker full access to their funds.
Fortunately, Trezor acted swiftly, disabling the malicious domain at the DNS level within 20 minutes of discovering the issue. However, about 2,500 subscribers had already clicked the link before it was taken down. Trezor assured users that no wallet data, passwords, or sensitive product information were compromised, as only opt-in newsletter email addresses were stored in the Brevo account.
Trezor took immediate steps to protect its users, treating all 347,000 email addresses as compromised and warning of potential future phishing attempts. The company has since suspended its Brevo account and implemented warning messages across its website, app, and support channels.
BitBox also reported that its entire newsletter and tutorial list was reached through the same Brevo vulnerability, but confirmed there was no evidence of downloaded contacts or lost funds. The company stated that only email addresses and language preferences were stored in its account.
CoinTracking’s Brevo account was similarly exploited, with users receiving an email titled “Data Breach Notice: Please refresh API Keys as soon as possible.” The firm promptly advised users against clicking any links contained in that email.
In light of this breach, Trezor has urged users who may have entered their wallet backups after clicking the malicious link to transfer their funds to a new wallet immediately. Users who clicked the link but did not enter any information are not at risk.
As a precautionary measure, Trezor is currently reviewing its vendor relationships and security protocols to prevent similar incidents in the future. The incident serves as a stark reminder of the vulnerabilities that can exist within third-party services and the importance of vigilance among crypto users.
