Key facts
- Brevo's login flaw allowed attackers to access 138 client accounts.
- A phishing email was sent to 347,000 Trezor newsletter subscribers.
- The attacker created a Brevo account, enabled single sign-on, and invited legitimate users, but an authorization boundary failure granted wider access.
- Trezor disabled the phishing domain within 20 minutes.
- About 2,500 people accessed the malicious link before it was taken down.
- BitBox and CoinTracking also reported unauthorized emails sent through their Brevo accounts.
An attacker exploited a flaw in the login system of email service provider Brevo, leading to phishing attacks targeting users of several cryptocurrency-related companies. The breach allowed access to 138 client accounts, from which fraudulent emails were sent to approximately 347,000 Trezor newsletter subscribers. Similar phishing messages were also distributed to users of hardware wallet maker BitBox and crypto portfolio tracker CoinTracking.
Brevo stated that the attacker created a new account, enabled single sign-on, and invited legitimate Brevo users. While access should have been limited to the attacker's organization, a failure in the authorization boundary granted access to other organizations the invited users could reach. The platform reported that six accounts were used to send phishing emails, contacts were exported from 43 accounts, and 93 accounts showed no significant activity.
Trezor confirmed that the phishing email, titled “Critical Security Alert: STM32 Entropy Vulnerability,” contained a link to a malicious app designed to steal wallet backups. The company disabled the associated domain at the DNS level within 20 minutes, but not before around 2,500 individuals had accessed the link. Trezor is treating all 347,000 affected newsletter addresses as potentially compromised and reusable for future phishing attempts. BitBox and CoinTracking also issued warnings, stating that their Brevo accounts only stored email addresses and language preferences, and they are awaiting further logs from Brevo.