Light bulb Limited Spots Available: Secure Your Lifetime Subscription on Gumroad!

Sep 11, 2026 · 6 min read

Brevo Hack Sent Fake Trezor Alerts to Crypto Users

Nothing about the email was spoofed. It left Trezor's real mailing list, through Trezor's real sending infrastructure, signed with Trezor's real keys, and landed in 347,000 inboxes warning of a firmware flaw that does not exist.

No password was cracked to make that happen. An attacker created an ordinary account on Brevo, the Paris email marketing platform formerly called Sendinblue, switched on single sign on, and invited existing Brevo users into the configuration. An authorization check meant to keep that access inside one organization did not hold, and the door opened onto 138 customer accounts, among them Trezor, BitBox and CoinTracking.

Key Takeaways

  • Attackers reached 138 Brevo customer accounts, exported contact lists from 43 of them, and used 6 to send phishing mail to those companies' subscribers.
  • Trezor's fake alert, subject line "Critical Security Alert: STM32 Entropy Vulnerability," reached roughly 347,000 subscribers and pointed at an app asking for wallet backups; about 2,500 opened the link before Trezor killed the domain in 20 minutes.
  • CoinTracking customers got a separate lure, "Data Breach Notice: Please refresh API Keys as soon as possible," and BitBox confirmed unauthorized newsletter activity on the same platform.
  • Because the companies' own email provider genuinely sent the mail, SPF, DKIM and DMARC all validated, so no gateway had grounds to reject it.
A small black hardware cryptocurrency wallet on a dark wooden desk beside an open laptop, a coffee cup and a phone, lit by soft low light

What Went Wrong Inside Brevo?

An authorization boundary in Brevo's single sign on flow failed, so access granted inside one attacker controlled organization extended to every organization the invited users could already reach. Sign up, enable SSO, invite real Brevo users, inherit their rights. Brevo's postmortem confirms that six accounts were used to send phishing mail while contacts were exported from 43 and 93 showed no meaningful activity.

"The bad actor used the access to send phishing emails to the client's contactbase," Brevo said. "The access has been closed."

Notice what is missing. No stolen credentials, no infostealer log, no session replay. A logic error in an invite flow did what a phishing kit spends weeks on, and multifactor authentication on those 138 accounts would have changed nothing, because nobody logged into them in the ordinary sense.

Why Did the Fake Trezor Email Pass Every Check?

Because Trezor's email provider really did send it, using authority Trezor had legitimately delegated. Authentication answers one narrow question: did this come from infrastructure the domain owner permits? Here, yes.

DKIM signs mail with a private key whose public half sits in the sending domain's DNS, per RFC 6376; DMARC, in RFC 7489, checks that the domain a reader sees aligns with the one that passed. Onboarding a provider means publishing its keys and authorizing its hosts, so taking the account turns every protection in your favor. The same pattern appeared when a crypto campaign routed phishing through Google's own account notification system.

The Marketing Stack Made the Lure Credible

Marketing platforms rewrite every link to count clicks, so the hostname you see on hover belongs to the platform, not the brand. Subscribers have spent a decade learning that an unfamiliar domain inside a newsletter link is normal. That training is worth money to whoever holds the account, and it runs on the infrastructure in our breakdown of how Brevo tracks your email and how to block it.

Then there is what got exported. A contact list on Brevo is not a column of addresses. It carries the engagement history the tracking pixel built: who opened, when, how often, on which device. Export it and you have a ranked list of which crypto holders actually read their mail. Blocking pixels with Gblock will not stop a takeover at the sender's end, but it keeps your reading habits out of the profile that leaks when one happens. To audit your inbox, start with detecting tracking pixels in Gmail.

What Did the Phishing Emails Ask For?

The Trezor lure invented a hardware flaw as a pretext to collect wallet backups. Its subject borrows the vocabulary of a real advisory, naming the STM32 microcontroller family used in hardware wallets. The link led to an app requesting recovery seeds, and a seed typed anywhere but the device is a wallet handed over, irreversibly.

CoinTracking subscribers got a quieter pitch, an API key refresh notice carrying malicious links; exchange keys expose portfolio positions and, depending on scope, more. BitBox confirmed unauthorized newsletter activity and reported no lost funds.

"Do not click on any link," Trezor told customers. "We have taken down the domain, and we are investigating the situation, including how the hackers got access to our legit domain." The takedown landed inside 20 minutes; roughly 2,500 got there first, seven tenths of one percent of 347,000. Any marketer would call that a failed campaign, which is the wrong yardstick: this one put a five figure crowd one form submission away from an empty wallet. The Record reports that Trezor is treating all 347,000 addresses as potentially exposed.

Haven't Trezor Customers Been Here Before?

Twice, both times through a supplier rather than the product. In April 2022 a social engineering attack on Mailchimp staff produced a phishing newsletter pointing at a fake Trezor Suite download, with 106,856 customer records exposed. Last month it was a fulfillment partner, when a breach at ShipMonk exposed 13,689 Trezor customers. Now the email platform.

Three incidents, three vendors, one constant: the hardware wallet has never been the thing that broke. Cold storage assumes the seed never leaves the device, and that holds. The perimeter around the list of people who bought one does not.

What This Means for Your Inbox

Your inbox runs on an assumption this breach quietly voids: that mail from a brand reflects that brand's intent. Nearly every company you hear from delegates its sending, and few platforms do that work. Brevo, Mailchimp, Klaviyo, SendGrid and a handful of peers sit between you and thousands of senders you trust, so one authorization bug travels further than any spoofing campaign, against a bank's list as readily as a wallet maker's. That concentration is the risk NIST SP 800-161r1 on cybersecurity supply chain risk management exists to describe.

Which makes most inherited phishing advice useless. Checking the sender domain does nothing when the domain is correct. There is no misspelling to catch and no padlock missing from anywhere. What remains is behavioral: does this ask me to type a secret, and would this company plausibly ask by email? For a recovery seed the answer is never, including a check that claims to protect you.

What Should You Do Now?

If you were on one of those lists, assume your address now circulates as a confirmed crypto holder. If you send marketing mail, the UK NCSC supply chain security collection is the right checklist to work from.

  • Never type a recovery seed anywhere but the device. No manufacturer asks for it by email, form, app or support chat. A message that recites this rule before asking you to break it is the scam.
  • Navigate manually and rotate keys from the site, not the link. CoinTracking customers were told to refresh API keys by an attacker. Doing it is good advice; doing it through their link is not.
  • Audit who can be invited into your SSO configuration. The failure was an invitation flow, not a login, so review tenant boundaries and cross organization visibility everywhere your customer list lives.
  • Check contact export logs. Exports from 43 accounts keep paying out for years, long after a phishing domain is gone.

Looking Ahead

The uncomfortable detail in Brevo's own account of the incident is how cheap it was. Nobody bought a zero day or wrote a line of malware. Somebody probed an invitation flow, found a boundary that did not hold, and walked off with the sending reputation of several established brands. That is a shape of bug rather than a Brevo specific one, and multi tenant SaaS is full of it.

Authentication cannot fix it, because authentication works correctly throughout. Until the platforms repair their permission models, stop reading a valid DKIM signature as evidence that a human meant to send you anything. The same lesson arrived from a different direction weeks later, when Revolut handed over passport scans to a request sent from a real government email domain. Days later, on September 14, Brevo was hit again, this time through its own scripts: a leaked Cloudflare key let attackers push ClickFix onto 100,000+ customer sites.

Stop Email Tracking in Gmail

Spy pixels track when you open emails, where you are, and what device you use. Gblock blocks them automatically.

Try Gblock Free for 30 Days

No credit card required. Works with Chrome, Edge, Brave, and Arc.