Skip to content
Back to Guavy Wire
Crypto

Brevo Login Flaw Exposes 347K Trezor Users to Phishing Attacks

Share

A security flaw in Brevo's login system was exploited by an attacker to send phishing emails to approximately 347,000 Trezor newsletter subscribers. The attack also affected BitBox and CoinTracking users.

Brevo reported that six of its accounts were used to send the phishing emails, which included a link to an app designed to solicit wallet backups. Trezor said it disabled the domain at the DNS level within about 20 minutes but still reported that around 2,500 people accessed the link before it was blocked.

Trezor emphasized the broader risk to its subscriber list and is treating all approximately 347,000 newsletter addresses as known to the attacker and possibly reusable for phishing. Other crypto firms affected by the Brevo login flaw include BitBox and CoinTracking, which reported no evidence of compromised company credentials or stolen funds.

The incident highlights the importance of being cautious when receiving unsolicited security prompts via email. Recipients should verify warnings through official channels and avoid entering sensitive data into links from untrusted messages.

More on Crypto

Disclaimer: Guavy is a data and market intelligence provider, not an investment adviser. The information, signals, and market analysis provided by the Guavy API and related services are for informational purposes only and are not intended as financial advice, investment recommendations, or an endorsement of any particular trading strategy. Trading in volatile markets, including cryptocurrency, carries significant risk and may not be suitable for all investors. Past performance is not indicative of future results. Users should consult with a qualified financial professional before making any investment decisions. Guavy makes no guarantee of trading profits or financial returns.

Market sentiment intelligence for apps, funds & agents

Location

729 55 Ave SW
Calgary AB T2V 0G4
Canada

© 2026 Guavy Inc