Brevo login flaw enabled phishing email targeting 347K Trezor subscribers
Trezor told Cointelegraph that the phishing email was sent to 347,000 subscribers and said it is treating every address as “known to the attacker and possibly reusable for phishing.”

Trezor told Cointelegraph that the phishing email was sent to 347,000 subscribers and said it is treating every address as “known to the attacker and possibly reusable for phishing.”
An attacker exploited a flaw in email platform Brevo’s login system to access 138 client accounts, enabling a phishing email to reach roughly 347,000 Trezor newsletter subscribers and similar fraudulent messages to be distributed through accounts belonging to hardware wallet maker BitBox and crypto portfolio tracking and tax-reporting platform CoinTracking.
In a Thursday postmortem, Brevo said six accounts were used to send phishing emails, contacts were exported from 43 and 93 accounts showed no meaningful activity. The platform did not specify whether the categories overlapped.
In a blog post, Trezor said the phishing message, titled “Critical Security Alert: STM32 Entropy Vulnerability,” contained a link to an app that requested users’ wallet backups. The company disabled the domain at the DNS level within 20 minutes, but about 2,500 people accessed the link before the takedown.