Brevo Email Platform Hack Exposes Dozens of Crypto Companies' Accounts
A security incident at Brevo, the third-party email platform used by Solana Mobile, has exposed at least 138 customer accounts, including those of prominent crypto companies. The breach was caused by a flaw in Brevo's SAML single sign-on system, which allowed an attacker to access multiple customer accounts.
Solana Mobile confirmed that its marketing account had been accessed without authorization, but stated it had no evidence of any unauthorized emails being sent from its account. However, the company warned its subscribers to treat any email claiming to be from Solana Mobile with suspicion, particularly those asking for sensitive information such as seed phrases or private keys.
The incident highlights the vulnerability of marketing platforms in the crypto industry, which are often used by companies without proper security measures in place. Brevo has since fixed the SSO boundary issue and is working with affected customers to determine the scope of the breach.