Brevo Login Flaw Leads to Phishing Attack on 347K Trezor Users

Topics: blockchain · Difficulty: începător

Attila Kiraly — Strateg AI & Educator · · 3 min read

Ilustrație a unui e-mail de phishing care vizează un portofel hardware crypto într-un mediu digital securizat.

Originally published: September 11, 2026

A security flaw at email marketing provider Brevo enabled attackers to send malicious phishing emails to 347,000 Trezor subscribers, as well as users of BitBox and CoinTracking.

What happened

Brevo, a prominent email marketing service provider, recently confirmed a critical authentication flaw that allowed malicious actors to gain unauthorized access to several corporate accounts. Among the affected entities were major crypto industry players, including hardware wallet manufacturer Trezor, BitBox, and the portfolio tracking tool CoinTracking. The attackers leveraged this access to dispatch sophisticated phishing emails to a database of approximately 347,000 Trezor subscribers, attempting to lure them into revealing their sensitive recovery seeds.

Technology context

This incident is a classic example of a supply chain attack. It is important to note that the blockchain itself and the physical security of Trezor hardware wallets remained uncompromised. Instead, the vulnerability resided in a third-party SaaS (Software as a Service) platform. By exploiting a weakness in Brevo's login protocols, hackers were able to use legitimate delivery infrastructure to send fraudulent messages. Because these emails originated from Brevo's verified servers, they successfully bypassed many standard anti-spam and anti-phishing filters.

Why it matters

The breach highlights a significant paradox in the crypto world: while decentralized assets are secured by robust mathematics, the centralized communication channels used by crypto firms remain a weak link. For the 347,000 affected users, the implications are long-lasting. Their email addresses are now tagged by attackers as belonging to crypto holders, making them high-value targets for future social engineering campaigns, even if they didn't fall for this specific scam.

Key terms explained

Impact

In the short term, there is a heightened risk of asset theft for any user who interacted with the malicious links. Trezor has officially stated that these 347,000 addresses are now "known to the attacker," suggesting a permanent increase in spam and phishing risks for these individuals. In the medium term, the industry is likely to see a shift in how crypto companies manage third-party risks, with a move toward stricter vendor audits and mandatory hardware-based Multi-Factor Authentication (MFA) for all marketing tools.

What's next

Moving forward, we anticipate a push for "Verified Communications" in the Web3 space. This could involve the use of blockchain-based signatures to verify the origin of corporate emails or the adoption of decentralized messaging protocols that do not rely on centralized email servers. Furthermore, hardware wallet manufacturers will likely intensify their educational efforts, emphasizing that a recovery seed must never be typed into any digital interface, regardless of how legitimate the request appears.

Sources

*

Educational analysis generated by AI and editorially reviewed.

Original source: cointelegraph.com

Want to learn the fundamentals? What is Blockchain?

Frequently Asked Questions

Was my Trezor hardware wallet hacked?

No, the physical device was not compromised. Only the email database at the service provider Brevo was accessed to send fraudulent messages.

What should I do if I received the phishing email?

Do not click any links and never enter your recovery seed on any website. Delete the email immediately.

How did attackers send emails appearing to be from Trezor?

They exploited an authentication flaw in Brevo, the third-party platform Trezor used for its marketing communications.

Am I safe if I didn't open the email?

Yes, you are safe, but your email address is now on an attacker's list. Be extremely vigilant regarding future communications.

Should I replace my hardware wallet?

There is no need to replace the device itself. However, if you ever typed your seed phrase into a website, move your funds to a new wallet with a new seed immediately.

Glossary Terms

Continue Learning

Explore more insights about technology, automation, and Web3 in the EduWeb Academy.

Explore Academy