Brevo Flaw Exposes Crypto Users to Phishing Attacks
A security flaw in Brevo's login system allowed an attacker to access 138 client accounts and send phishing emails to hundreds of thousands of crypto users.
The breach affected Trezor, BitBox, and CoinTracking, all of which used Brevo to manage their newsletter lists. The attacker created a Brevo account, enabled single sign-on, and invited legitimate Brevo users into the setup, granting them access to every organization those invited users could reach.
Trezor's 347,000 newsletter subscribers received an email with the subject line 'Critical Security Alert: STM32 Entropy Vulnerability.' The email contained a link to a fake app that asked users to enter their wallet backup, which would give attackers full access to their funds. Trezor disabled the domain at the DNS level within 20 minutes of discovering the email.
About 2,500 people had already clicked the link before it was taken down. Trezor confirmed that only opt-in newsletter email addresses were stored in its Brevo account. No passwords, wallet data, or other personal information was held there.