Brevo Login Flaw Leads to Phishing Attacks Against Trezor and BitBox Users
Security vulnerability impacts hundreds of thousands of crypto subscribers
A technical flaw in the login system of email platform Brevo allowed attackers to send phishing emails to approximately 347,000 Trezor subscribers. The breach also affected other crypto-related firms, including the hardware wallet maker BitBox and the tax-reporting platform CoinTracking. A hardware wallet is a physical device that stores the private keys needed to access and manage cryptocurrency offline.
The attackers exploited a weakness in Brevo's authorization process to gain access to 138 client accounts. This enabled them to send genuine-looking emails that passed standard security checks. Trezor, BitBox, and CoinTracking have all issued warnings to their users regarding the fraudulent messages.
Impact of the Brevo security breach
- 347,000 Trezor newsletter subscribers received the phishing email.
- About 2,500 people clicked the malicious link before it was disabled.
- Attackers accessed 138 client accounts on the Brevo platform.
- The breach affected multiple crypto companies using the same email service provider.
Technical failure in Brevo login system
According to a postmortem report from Brevo, the attacker exploited a flaw in the platform's single sign-on (SSO) configuration. The attacker created an account and invited legitimate users, but a failure in the "authorization boundary" allowed the attacker to access every organization those users were connected to.
Brevo confirmed that six accounts were used to send phishing emails. Additionally, contact lists were exported from 43 accounts, while 93 other accessed accounts showed no significant activity. The company did not specify if these categories overlapped.
How crypto firms were affected
Trezor reported that the phishing email, titled "Critical Security Alert: STM32 Entropy Vulnerability," directed users to a malicious app that requested their wallet backups. Trezor was able to disable the fraudulent domain within 20 minutes of the attack starting. The company stated that their Brevo account only contained newsletter email addresses and no other customer data.
BitBox confirmed that an unauthorized email was sent to its entire newsletter and tutorial list. While the company found no evidence of lost funds or stolen recovery phrases, it is treating its contact list as potentially compromised. CoinTracking also warned its users about a fraudulent email titled "Data Breach Notice" that asked recipients to refresh their API keys.
Confirmed details of the attack
It is confirmed that a technical flaw in Brevo's SSO system was the root cause of the unauthorized access. Trezor has confirmed that 347,000 of its subscribers were targeted and that 2,500 individuals accessed the phishing link. All three companies—Trezor, BitBox, and CoinTracking—have confirmed that the phishing messages originated through their official Brevo accounts.
Uncertainties regarding data exposure
It remains unclear whether the attackers successfully stole funds from any users who clicked the links. BitBox is still awaiting detailed logs from Brevo to determine if its contact lists were fully downloaded. While Brevo identified how many accounts were accessed, it has not provided a complete list of all affected clients beyond the crypto firms that have publicly come forward.
Ongoing risks for affected users
Trezor is now treating all 347,000 newsletter email addresses as "known to the attacker." The company warned that these addresses could be used for future phishing attempts. Users are advised to remain cautious of any emails requesting wallet backups, recovery phrases, or API key updates, even if the messages appear to come from official sources.