TLDR
- A flaw in email platform Brevo’s login system gave an attacker access to 138 client accounts
- Around 347,000 Trezor newsletter subscribers received a phishing email containing a malicious link
- BitBox and CoinTracking were also affected through their Brevo accounts
- About 2,500 people clicked the link before Trezor took down the domain within 20 minutes
- Trezor says no wallet data, passwords, or product systems were compromised
A security flaw in email marketing platform Brevo allowed an attacker to access 138 client accounts and send phishing emails to hundreds of thousands of crypto users.
🚨 SECURITY WARNING 🚨
Brevo (formerly Sendinblue) has reportedly been compromised. Phishing emails impersonating CoinTracking, Trezor and BitBox and likely several others in the industry are currently making the rounds.
DO NOT:
❌ Click any links
❌ Download attachments
❌… pic.twitter.com/yW30XrNV1R— Coinjoined Chris ⚡ (@coinjoined) September 9, 2026
The breach affected Trezor, BitBox, and CoinTracking, all of which used Brevo to manage their newsletter lists.
How the Attack Worked
The attacker created a Brevo account, enabled single sign-on, and invited legitimate Brevo users into the setup. An authorization boundary failure then granted the attacker access to every organization those invited users could reach.
Brevo later confirmed that six accounts were used to send phishing emails, 43 had contacts exported, and 93 showed no meaningful activity.
The attack was structured to bypass normal email authentication checks, making the messages appear genuine to recipients.
What Trezor Subscribers Received
Trezor’s 347,000 newsletter subscribers received an email with the subject line “Critical Security Alert: STM32 Entropy Vulnerability.”
The email contained a link to a fake app that asked users to enter their wallet backup, which would give attackers full access to their funds.
Trezor disabled the domain at the DNS level within 20 minutes of discovering the email. About 2,500 people had already clicked the link before it was taken down.
Trezor confirmed that only opt-in newsletter email addresses were stored in its Brevo account. No passwords, wallet data, or other personal information was held there.
The company is treating all 347,000 addresses as potentially known to the attacker and at risk of future phishing attempts.
BitBox and CoinTracking Also Hit
BitBox said the unauthorized email appeared to reach its full newsletter and tutorial list through Brevo. The company found no evidence of downloaded contacts, lost funds, or exposed recovery phrases.
BitBox confirmed Brevo held only email addresses and language preferences for its subscribers.
CoinTracking’s Brevo account was used to send an email titled “Data Breach Notice: Please refresh API Keys as soon as possible.” The company warned users not to follow any links in that email.
Trezor has suspended its Brevo account and added warning messages across its website, app, and support channels.
If you entered your wallet backup after clicking the link, Trezor advises moving funds to a new wallet immediately. Clicking the link without entering anything does not put your funds at risk.
Trezor says it is reviewing its vendor relationships and security requirements following the incident.







