NewsCryptoBrevo Login Flaw Exposed Trezor, BitBox and CoinTracking Email Accounts

Brevo Login Flaw Exposed Trezor, BitBox and CoinTracking Email Accounts

Author: Cointelegraph·

Key Takeaways

  • Brevo said an authorization-boundary failure allowed the attacker to access organizations associated with invited legitimate users.
  • The attacker sent a phishing email to approximately 347,000 Trezor subscribers, and around 2,500 people opened its link before the domain was disabled.
  • Trezor said its Brevo account contained only opt-in newsletter addresses and no other customer information.
  • BitBox reported that its email and language-preference data may have been accessed but found no evidence of compromised credentials, lost funds or exposed recovery phrases.
  • Brevo reported that contacts were exported from 43 accounts, while six accounts sent phishing messages and 93 showed no meaningful activity.
Brevo Login Flaw Exposed Trezor, BitBox and CoinTracking Email Accounts

An attacker exploited a flaw in email platform Brevo’s login system to access 138 client accounts, allowing phishing emails to be sent to roughly 347,000 Trezor newsletter subscribers and enabling similar fraudulent messages through accounts belonging to hardware wallet maker BitBox and crypto portfolio tracking and tax-reporting platform CoinTracking.

In a Thursday postmortem, Brevo said six accounts were used to send phishing emails, contacts were exported from 43 accounts, and 93 accounts showed no meaningful activity. The company did not specify whether those categories overlapped.

The attacker created a Brevo account, enabled single sign-on and invited legitimate Brevo users into its configuration. Brevo said access should have remained limited to that organization. However, an authorization boundary failed, granting the attacker access to every organization that the invited users could reach.

The disclosure provides additional detail following warnings from Trezor and BitBox on Wednesday. It identified the two companies’ shared email provider and explained why the fraudulent messages passed normal authentication checks and appeared genuine. Cointelegraph contacted Brevo for further information but had not received a response before publication.

The reported exposure concerns email accounts and mailing-list data; the companies’ statements separately address whether credentials, funds or recovery phrases were compromised. The full scope for affected clients remains dependent on provider records, with BitBox awaiting Brevo’s logs and Brevo yet to provide further information in response to Cointelegraph’s inquiry.

Crypto firms assess potential subscriber exposure

In a blog post, Trezor said the phishing message, titled “Critical Security Alert: STM32 Entropy Vulnerability,” included a link to an application that requested users’ wallet backups. Trezor disabled the domain at the DNS level within 20 minutes, but approximately 2,500 people accessed the link before it was taken down.

A Trezor spokesperson told Cointelegraph that “the initial email was sent to 347,000 customers.” The company subsequently contacted all of them about the risk. Trezor said its Brevo account contained only opt-in newsletter email addresses and no other customer data.

“Until we hear more from Brevo, we are treating all roughly 347,000 newsletter addresses as known to the attacker and possibly reusable for phishing,” the spokesperson said.

A BitBox spokesperson told Cointelegraph that its unauthorized email was sent through Brevo and appeared to have reached the company’s full newsletter and tutorial list. BitBox said Brevo held only email addresses and language preferences. It found no evidence that company credentials had been compromised, contacts downloaded, funds lost or recovery phrases disclosed. However, it is treating the list as potentially accessed while awaiting Brevo’s logs.

CoinTracking said its Brevo account distributed an email titled “Data Breach Notice: Please refresh API Keys as soon as possible.” The company warned recipients not to follow links in the message. Cointelegraph’s report is available at https://cointelegraph.com/news/brevo-login-flaw-trezor-bitbox-cointracking-phishing.