A security flaw at email marketing provider Brevo allowed an attacker to access customer accounts and distribute convincing phishing messages through legitimate company infrastructure, affecting Trezor, BitBox and CoinTracking. The campaign reached roughly 347,000 Trezor newsletter subscribers, demonstrating how a third-party communications platform can become a high-impact attack vector even when hardware wallets and internal company systems remain uncompromised.
In its official incident report, Trezor said the September 9 campaign used the subject “Critical Security Alert: STM32 Entropy Vulnerability” and directed recipients toward software requesting their wallet backup. Trezor disabled the malicious domain within approximately 20 minutes, but around 2,500 recipients had already accessed the link, while the company subsequently treated all 347,000 newsletter addresses as potentially known to the attacker.
Brevo SSO Flaw Crossed Account Boundaries
Brevo’s subsequent postmortem identified an authorization-boundary failure involving single sign-on. The attacker reportedly created a Brevo organization, enabled SSO and invited legitimate users into it. Instead of restricting those users to the malicious organization, the flaw exposed other Brevo organizations they were authorized to access, allowing the attacker to move across customer accounts.
The final incident count reached 138 affected Brevo accounts, expanding on an earlier figure of 120 cited by Trezor. Six accounts were reportedly used to distribute phishing emails, while contacts were exported from 43 and 93 showed no meaningful malicious activity. The breach was therefore both an account-access incident and, for some customers, a potential subscriber-data exposure.
CoinTracking separately confirmed through its official security notice that its third-party email provider had been breached. Attackers sent customers messages instructing them to refresh API keys, creating a separate credential-theft route from the recovery-seed campaign targeting Trezor users. The same compromised communications layer was adapted to steal different secrets depending on the service being impersonated.
Supply-Chain Phishing Raises Wallet Risk
The Trezor campaign was particularly dangerous because emails sent through legitimate infrastructure could appear authentic and pass checks users normally rely on to detect spoofing. A valid-looking sender does not make a request for wallet recovery words legitimate, leaving the content and requested action as critical security signals when trusted communication infrastructure itself has been compromised.
Trezor said Brevo contained only its opt-in newsletter email addresses and no passwords, wallet information or other customer data. The company also stressed that its wallets, products and account systems were unaffected. Users who merely received or opened the phishing message remain safe unless they disclosed their wallet backup, while anyone who entered a recovery seed must consider that wallet compromised and move assets to a newly generated wallet immediately.
The incident ultimately exposes a security dependency outside the hardware wallet itself. Crypto companies can protect private keys while remaining vulnerable through marketing, logistics and communication vendors, making tenant isolation, least-privilege access and third-party incident response increasingly important components of self-custody security.
