📈 Get daily crypto insights that make you smarter about your money

How a Broken Email Login Let Attackers Phish 347,000 Trezor Subscribers — The Brevo Postmortem Explained

The phishing emails that hit roughly 347,000 Trezor newsletter subscribers this week were not the result of a wallet-company breach — they came from a security failure at an email marketing provider. Brevo, the platform used by Trezor and other crypto firms, has published a postmortem explaining exactly how attackers turned legitimate mailing infrastructure into a weapon.

By Amir Hassan | September 11, 2026

The Hook: A Broken Permission Boundary, Not a Hack of Trezor

In a Thursday postmortem, Brevo said the attacker exploited a weakness involving its single sign-on system, gaining access to organizations connected to legitimate users who had been invited into an attacker-controlled Brevo account. The incident affected 138 customer accounts in total: six were used to send phishing emails, contacts were exported from 43 accounts, and Brevo recorded no meaningful activity across another 93. The company did not specify whether those groups overlapped.

The attack chain was simple and clever. The attacker first created a Brevo account and enabled single sign-on, then invited legitimate Brevo users into the newly created organization. Access should have remained limited to the attacker-controlled organization. Instead, Brevo said an authorization boundary failed, allowing the attacker to reach every organization that the invited users themselves had permission to access.

Think of it like this: you accept an invitation to someone’s shared office, and a flaw in the building’s keycard system suddenly hands you the master key to every office your co-workers can enter. The compromised accounts included those used by hardware wallet makers Trezor and BitBox, and crypto portfolio tracking and tax-reporting service CoinTracking.

The Evidence: Why the Phishing Was So Convincing

Because the fraudulent messages were sent through legitimate mailing infrastructure, they could pass normal email authentication checks and reach subscribers from addresses associated with the affected companies. In other words, the emails looked exactly like real company communications because, from the email system’s point of view, they were.

  • The lure: Trezor’s phishing email used the subject line “Critical Security Alert: STM32 Entropy Vulnerability” and described a supposed hardware security problem requiring user action
  • The goal: recipients were directed to a malicious application that requested their wallet backups — the recovery phrase that controls all funds in a wallet
  • The scale: Trezor’s Brevo account contained roughly 347,000 opt-in newsletter email addresses, with no other customer information stored on the platform
  • The response: Trezor took the malicious domain offline at the DNS level within 20 minutes; around 2,500 people had accessed the link before the takedown

A Trezor spokesperson told Cointelegraph that the initial phishing message was sent to all 347,000 addresses, and that the company subsequently contacted the same subscribers to warn them about the attack. “Until we hear more from Brevo, we are treating all roughly 347,000 newsletter addresses as known to the attacker and possibly reusable for phishing,” the spokesperson said.

The Core Conflict: Your Wallet Was Never the Problem

Trezor said the Brevo incident did not compromise its hardware wallets, wallet backups or other internal systems. Customers who did not enter their wallet backup into the malicious application remained safe, according to the company. That distinction is the most important takeaway of the whole incident: the security of the hardware wallet itself was never in question — the attack targeted the humans around it.

The campaign also fits a wider pattern. In August, a Trezor user said he lost his life savings after a sponsored Google search result directed him to a fake website hosted through Google Sites. Trezor said at the time it was seeing more phishing websites impersonating the company through sponsored search results. Earlier in 2026, scammers sent fake Trezor and Ledger letters to hardware wallet owners containing QR codes that led to phishing websites requesting 12, 20 or 24-word recovery phrases under the pretext of completing authentication or transaction checks.

BitBox identified a similar campaign on Wednesday and warned users not to follow instructions in fraudulent emails sent under its name. Its initial investigation found that several Bitcoin companies had been targeted and appeared to share the same newsletter provider. BitBox contacted the provider, warned newsletter subscribers and reported the phishing domains while investigating how the emails had been distributed.

Market Implications: Third-Party Risk Is Crypto’s Soft Underbelly

For the broader industry, the incident is a reminder that crypto companies are only as secure as their supply chain. A hardware wallet can be engineered to perfection, but if the vendor’s email provider, marketing platform or support desk has a weak link, attackers will find it. The attack came just weeks after BitBox patched two of its own wallet vulnerabilities involving firmware installation and Bitcoin address handling, which the company said had not been exploited.

Regulators have taken notice of exactly this class of risk. US banking agencies have recently proposed guidelines around third-party risk management for banks engaging with outside technology providers — a signal that the Brevo-style failure mode, where a trusted partner becomes the attack vector, is now a board-level concern across financial services.

The Verdict: What You Should Actually Do

The practical guidance is unchanged and boring, which is exactly why it works. Never enter your recovery phrase on any website, no matter how urgent the message sounds — no legitimate wallet maker will ever ask for it. Treat any “critical security alert” arriving by email with suspicion, and verify news directly on the company’s official website instead of clicking links. If you received one of the Trezor or BitBox emails this week and did not interact with the malicious application, you have nothing to do beyond staying alert: your email address is likely known to the attacker and may be targeted again.

Hardware wallets remain one of the strongest ways to hold crypto long term. This week proved, once again, that the weakest link is rarely the hardware — it is the inbox.

The cryptocurrency market remains highly volatile. This article is for informational purposes only and does not constitute financial advice.

14 thoughts on “How a Broken Email Login Let Attackers Phish 347,000 Trezor Subscribers — The Brevo Postmortem Explained”

  1. Trezor points at Brevo, Brevo points at SSO, everybody points somewhere and 347k subscribers are left typing trezor.io by hand like it is 2013

  2. 347k people got phished because of one SSO invite. hardware wallet company, third party email provider, zero org level second factor. unreal

  3. Single sign-on was the weak link again. Companies push SSO for security and then one rogue invitation breaks the whole chain.

    1. SSO plus auto accepting org invites is quite the combo. nobody audits who invited them until 347k inboxes get phished from real infrastructure

      1. the worst part is the fix is like ten lines of code. pending org invites should expire after 30 days, that gap sat open for years

      2. brevo calling it a permission boundary thing after the fact is rich. pending org invites should have expired automatically years ago, 347k inboxes paid for that gap

  4. Six accounts sent the phishing mail but contacts were exported from 43. Those export lists are almost certainly sold and recycled by now.

    1. 43 exported contact lists from six sending accounts. those lists get resold forever, expect a wave of fake trezor compensation emails in a few weeks

Leave a Comment

Your email address will not be published. Required fields are marked *

BTC$77,366.00+0.1%ETH$2,538.67+2.9%SOL$102.63+2.5%BNB$725.69+1.5%XRP$1.36+0.5%ADA$0.2063-2.0%DOGE$0.0845+0.3%DOT$1.05-5.3%AVAX$7.47-1.9%LINK$11.60-0.2%UNI$6.06-0.6%ATOM$1.65-9.2%LTC$53.60+2.3%ARB$0.1413-4.7%NEAR$2.48-1.3%FIL$0.7837-2.0%SUI$0.7276-1.9%BTC$77,366.00+0.1%ETH$2,538.67+2.9%SOL$102.63+2.5%BNB$725.69+1.5%XRP$1.36+0.5%ADA$0.2063-2.0%DOGE$0.0845+0.3%DOT$1.05-5.3%AVAX$7.47-1.9%LINK$11.60-0.2%UNI$6.06-0.6%ATOM$1.65-9.2%LTC$53.60+2.3%ARB$0.1413-4.7%NEAR$2.48-1.3%FIL$0.7837-2.0%SUI$0.7276-1.9%
Scroll to Top