A login authorization flaw in email marketing platform Brevo allowed an attacker to access 138 customer accounts, including those used by Trezor. This enabled phishing emails to be sent from Trezor’s account to roughly 347,000 newsletter subscribers.
The messages, which appeared legitimate and passed standard email authentication checks, directed recipients to a malicious site requesting wallet backup phrases under the false claim of an STM32 entropy vulnerability. Similar activity affected accounts linked to BitBox and CoinTracking. Trezor’s own systems and wallets were not compromised.
The Drivers of This Incident
The attacker created a Brevo account, enabled single sign-on, and invited legitimate users into that configuration. An authorization boundary failure then granted access to every organization those users could reach, rather than limiting it to the attacker-controlled account. Six accounts were used to send phishing emails, while contact lists were exported from 43 others. For perspective, the campaign leveraged trusted marketing infrastructure, allowing the fraudulent Trezor email (subject: “Critical Security Alert: STM32 Entropy Vulnerability”) to reach a large subscriber base and draw about 2,500 clicks before the domain was disabled within 20 minutes.
It is important to note the fundamental difference between a direct compromise of a hardware wallet company’s core systems and a third-party provider breach that only exposes marketing contact lists and email-sending capabilities.
Impact and Broader Context
Trezor is treating all approximately 347,000 newsletter addresses as potentially known to the attacker and reusable for future phishing, while confirming that no wallet data, passwords, or product systems were affected. This development sparks important discussions about the risks of relying on third-party email and marketing platforms for crypto firms that handle sensitive user outreach. Supporters of rapid incident response highlight how Trezor quickly suspended the account, warned users, and contained the malicious domain, limiting potential damage. Critics point to recurring vulnerabilities in shared marketing tools as a systemic weak point that can undermine even strong self-custody practices. Analysts observe that such supply-chain-style incidents underscore the need for stricter access controls, multi-factor protections, and reduced dependence on external platforms for high-trust communications in the crypto sector.
Users are advised to remain vigilant against follow-up phishing attempts and never enter seed phrases in response to unsolicited alerts. This analysis is based on statements from Trezor, Brevo’s postmortem, and reports from crypto.news and Cointelegraph for accuracy and reliability. Further details on the full scope of affected accounts and any additional exposure remain subject to ongoing investigation.
