Trezor Phishing Emails Reached 347,000 Bitcoin (BTC) Wallet Subscribers via Brevo Breach

Trezor said fake emails reached 347,000 subscribers after a Brevo SSO breach; wallets were untouched and 2,500 users opened the phishing link.

(10:48 AM UTC)
4 min read
AI SummaryAI
  • Trezor said fake emails reached about 347,000 newsletter subscribers via compromised provider Brevo.
  • Trezor disabled the phishing domain within 20 minutes; about 2,500 recipients opened the link.
  • Brevo's postmortem found 138 client accounts accessed; six sent phishing and 43 had contacts exported.
  • The attacker exploited a single sign-on authorization flaw to reach multiple Brevo customer organizations.
k7rq2fdm

Trezor’s 20-Minute Domain Takedown

Hardware wallet maker Trezor disclosed on September 10 that attackers had compromised Brevo, the third-party email platform it uses for newsletter distribution, and used its account to send fake security alerts to roughly 347,000 subscribers. The fraudulent message, titled “Critical Security Alert: STM32 Entropy Vulnerability,” pushed recipients to install an application and enter their wallet backup — the recovery phrase that grants full control over a user’s funds. Because the emails were dispatched through Brevo’s genuine infrastructure, they passed SPF and DKIM — the standard sender-authentication checks — so filters and inboxes treated them as legitimate mail. Trezor stressed that its products, wallet infrastructure and account systems show no sign of intrusion, and that the compromised Brevo account stored nothing beyond opt-in newsletter addresses. The company disabled the malicious domain at the DNS level within 20 minutes of identifying the attack, but about 2,500 recipients still opened the phishing link before the takedown. Warnings were posted not only by email but across Trezor’s official website, the Trezor Suite app and its support channels. A Trezor spokesperson said the firm is treating all 347,000 addresses as known to the attacker and possibly reusable for future phishing campaigns until Brevo shares more detail. Trezor reiterated that it never asks users to enter a wallet backup by email, and it has published official instructions for anyone who typed a recovery phrase into the fake site, urging them to move funds to a newly created wallet immediately — a standard transfer to fresh keys, not a cross-chain operation like an atomic swap. Markets shrugged off the incident: Bitcoin (BTC) changes hands near $77,000 at press time, and the daily candlestick on the BTC chart shows no material reaction to the disclosure.

138 Brevo Accounts Compromised

Brevo’s own postmortem, published Thursday, explains how a single login flaw reached so many crypto firms at once. The attacker first created a Brevo account and enabled single sign-on (SSO) — an authentication setup that lets one set of credentials log into multiple services — then invited legitimate Brevo users into that configuration to establish a foothold. Access should have been confined to the attacker’s organization, but an authorization boundary failed and extended to every organization the invited users could reach. According to Brevo’s incident report, 138 client accounts were affected in total: six were abused to send phishing emails, contacts were exported from 43, and 93 showed no meaningful activity. Trezor’s account was one of the six used for the mailing. The same flaw also exposed accounts at BitBox, another hardware wallet maker, and CoinTracking, a crypto portfolio tracking and tax-reporting platform. A BitBox spokesperson said the unauthorized email appeared to have reached its full newsletter and tutorial list, adding that Brevo stored only email addresses and language preferences, with no evidence of compromised company credentials, downloaded contacts, lost funds or disclosed recovery phrases. CoinTracking warned recipients in an official post that its account had distributed a message titled “Data Breach Notice: Please refresh API Keys as soon as possible,” telling users not to follow the email’s links. Brevo says it identified the unauthorized access on September 10, cut off the intrusion path roughly two hours later, and forced the termination of all user sessions, with no further access via the same method observed since. The company is limiting post-SSO access to the organization where SSO was configured, will keep the suspended SSO invitation feature disabled until the fix is complete, and says it is pursuing legal action while cooperating fully with authorities. Trezor has not confirmed whether the subscriber list itself was exfiltrated, since Brevo’s system held no passwords or wallet data. Readers tracking the market in real time can follow live spot and futures prices on MEXC.

Supply-Chain Vetting Comes Next

COINOTAG’s read: the attacker never touched a blockchain, an exchange or a single wallet — the entire compromise lived in email infrastructure. As embedded-link standards such as Solana Blinks and Actions make ordinary-looking links capable of triggering on-chain actions, the cost of one convincing click keeps climbing. Derivatives positioning confirms traders saw no protocol risk: funding on perpetual contracts tied to major assets held steady through the disclosure window. Brevo’s official write-up — the primary record here — states plainly that the SSO authorization boundary was the root cause and that remediation is still in progress. Users should treat any email requesting a recovery phrase as hostile by default, no matter how authentic the sender appears.

COINOTAG News Desk

COINOTAG News Desk

COINOTAG's editorial and research desk.

How our News Desk works
AI-Assisted

AI-generated, AI-reviewed, under COINOTAG editorial oversight.