Technology
Cointelegraph.com News

Brevo login flaw enabled phishing email targeting 347K Trezor subscribers

Source Entity

Cointelegraph by Ezra Reguerra

September 13, 2026
Brevo login flaw enabled phishing email targeting 347K Trezor subscribers

A security breach at marketing platform Brevo allowed hackers to send phishing emails to 347,000 Trezor subscribers. The malicious messages aimed to steal cryptocurrency wallet recovery phrases, marking the second major security incident involving a Trezor vendor in recent months.

The Brevo Security Breach: A Targeted Campaign Against Crypto Users

In a concerning development for the hardware wallet ecosystem, Trezor has confirmed a significant data breach stemming from a compromise at Brevo, their third-party email marketing provider. An attacker successfully exploited a vulnerability in Brevo’s login system, gaining unauthorized access to 138 client accounts. This breach facilitated a large-scale phishing campaign, with approximately 347,000 Trezor newsletter subscribers receiving fraudulent emails designed to compromise their digital assets.

Mechanics of the Phishing Attack

The attackers utilized sophisticated social engineering tactics, leveraging the trusted relationship between Trezor and its user base. The phishing emails, which carried the subject line “Critical Security Alert: STM32 Entropy Vulnerability,” directed users to a malicious link. Upon interaction, the link prompted the download of a deceptive application designed to harvest the victim's wallet backup password. Given the nature of hardware wallets, obtaining this seed phrase or password grants an attacker the ability to irreversibly drain funds directly from the public blockchain.

Breadth of the Compromise

The impact of the Brevo breach extended beyond Trezor, illustrating the systemic risks posed by centralized marketing platforms. Brevo’s postmortem revealed that six accounts were actively used to distribute phishing content, while contacts were exported from 43 accounts. Other prominent crypto-related entities, including the hardware wallet manufacturer BitBox and the tax-reporting platform CoinTracking, were also among the affected clients. This incident highlights the vulnerability of the supply chain when security flaws in third-party services provide attackers with a gateway to massive, curated lists of high-value targets.

Trezor’s Response and Security Outlook

Trezor has adopted a proactive, albeit defensive, posture in response to the breach. The company is currently treating every email address associated with the 347,000 subscribers as "known to the attacker," warning users that their contact information remains susceptible to future phishing attempts. This marks the second time in as many months that Trezor has had to alert its customer base regarding a breach involving a third-party vendor, underscoring the ongoing challenges of maintaining operational security in an increasingly interconnected digital landscape.

Implications for the Cryptocurrency Industry

This event serves as a stark reminder of the 'human element' in cybersecurity. Even with industry-leading hardware security, users remain the primary target for attackers who bypass technical defenses by exploiting service providers. As crypto-focused platforms continue to rely on third-party SaaS solutions for communication, the security of these vendors becomes as critical as the security of the primary product. Future trends will likely see a move toward stricter audit requirements and potentially decentralized communication alternatives to mitigate the risks inherent in centralized marketing databases.

Verification Required?

Read the full report from the primary source

Go to Cointelegraph.com News