Brevo flaw enabled phishing attack on 347K Trezor newsletter subscribers
In brief
- Brevo login flaw allowed attacker to access 138 client accounts and target 347,000 Trezor newsletter subscribers with phishing emails
- Phishing message impersonated critical security alert requesting wallet backups from recipients
- Trezor disabled malicious domain within 20 minutes; approximately 2,500 users clicked the link before takedown
- BitBox and CoinTracking also targeted; no compromised credentials or stolen funds reported
The Attack Vector
An attacker exploited a flaw in Brevo's login system to gain access to 138 client accounts. The attacker's method was methodical: create a Brevo account, enable single sign-on, and invite legitimate Brevo users into the configuration. When those invited users accepted, an authorization boundary in Brevo failed and granted access to every organization the invited users could reach.
Six accounts were used to send phishing emails, and contacts were exported from 43 Brevo accounts in the process. The scope was significant but contained by swift action.
The Phishing Campaign
The phishing email was sent to approximately 347,000 Trezor newsletter subscribers. The message was crafted to look urgent—titled "Critical Security Alert: STM32 Entropy Vulnerability"—and contained a link requesting users' wallet backups.
Approximately 2,500 people accessed the phishing link before the takedown. That's a 0.7% click rate on a massive list—a grim reminder that even small percentages of large targets yield substantial numbers.
Other hardware wallet projects weren't spared. BitBox received a phishing email through Brevo that reached its full newsletter and tutorial list. CoinTracking's Brevo account distributed a phishing email titled "Data Breach Notice: Please refresh API Keys as soon as possible".
Damage Assessment and Response
Trezor moved fast. The company disabled the domain at the DNS level within 20 minutes of discovering the attack. That speed likely prevented much worse outcomes.
Trezor's Brevo account stored only opt-in newsletter email addresses and no other customer data, which limited what the attacker could extract. Still, Trezor is taking the threat seriously. The company told Cointelegraph it's treating every address as compromised going forward.
Until we hear more from Brevo, we are treating all roughly 347,000 newsletter addresses as known to the attacker and possibly reusable for phishing.
BitBox's investigation found more positive news. The company found no evidence of compromised company credentials, downloaded contacts, lost funds or disclosed recovery phrases. That's the outcome everyone hopes for—a contained incident with no downstream theft.


