Brevo Login Flaw Used to Target 347,000 Trezor Subscribers in Crypto Phishing Spree
Attackers compromised a trusted email service provider to bypass security filters and solicit wallet seed phrases from cryptocurrency users.
A security vulnerability in the email service provider Brevo allowed attackers to compromise customer accounts and launch a sophisticated phishing campaign against cryptocurrency companies. The breach enabled bad actors to send fraudulent messages from legitimate domains, bypassing standard authentication checks to target thousands of users.
According to Brevo, the vulnerability led to the compromise of 138 customer accounts. The company confirmed that six of these accounts were used to distribute phishing emails, while 43 were used to export contact lists. Among the affected clients were crypto-focused firms Trezor, BitBox, and CoinTracking. Trezor reported that 347,000 of its newsletter subscribers were targeted by the campaign. The phishing lure specifically claimed a "Critical Security Alert: STM32 Entropy Vulnerability," asserting that one in four devices suffered from a hardware factory defect with 40-bit entropy. The goal of the messages was to trick users into revealing their private wallet seed phrases.
A Pattern of Exposure
This incident occurs amid a broader series of security challenges for Trezor. The company previously dealt with a separate breach at its logistics partner, ShipMonk, which exposed the personal details of approximately 81,000 customers. Security experts note that the combination of these two breaches—one involving communication and the other involving shipping logistics—significantly increases the risk of targeted attacks. This includes not only digital phishing but also the potential for physical "wrench attacks" or malicious postal mail directed at high-value cryptocurrency holders.
The Danger of Supply Chain Phishing
This attack highlights the severe risk of "supply chain" phishing, where attackers target a trusted third-party service provider rather than the primary target. Because the emails were sent through Brevo's legitimate infrastructure, they passed SPF and DKIM authentication. This means the messages were far more likely to land in users' primary inboxes and appear authentic compared to traditional spoofing attempts, which are often flagged by spam filters.
Security Guidance and Next Steps
In response to the campaign, Trezor has urged its users to remain vigilant and avoid interacting with suspicious emails. "Do not click it or interact with it. Never enter your wallet backup anywhere," the company stated, reminding users to always confirm every action physically on their Trezor device.
Industry observers are now watching for further evidence of how the Brevo vulnerability was exploited and whether other service providers are susceptible to similar login flaws. For now, the incident serves as a reminder that even when a company's own internal security is tight, the vulnerabilities of their vendors can create critical points of failure.