Skip to main content
Back to news
SafetyMajor story — Significance is rated automatically and is not a price signal.

Brevo Login Flaw Allowed Phishing Emails Sent to 347,000 Trezor Subscribers

(21 days ago) · 1 source · Summarized by CryptoBipto

A security vulnerability in email marketing platform Brevo was exploited to send phishing emails to approximately 347,000 Trezor hardware wallet subscribers. The flaw reportedly allowed attackers to gain access to Brevo's system and send fraudulent emails that appeared to come from legitimate crypto companies. Other crypto services such as BitBox and CoinTracking were also reportedly affected.

WHY IT MATTERS

Hardware wallets like Trezor are physical devices people use to store their cryptocurrency offline, which is considered one of the safest ways to hold crypto. However, the companies behind these wallets still use regular business tools like email marketing platforms to communicate with their customers. Think of it like a bank using a third-party mailing service to send you statements — if someone breaks into that mailing service, they can send fake letters that look real. In this case, attackers exploited a flaw in the email platform Brevo to send convincing fake emails to hundreds of thousands of crypto users. Phishing emails typically try to trick people into revealing passwords, recovery phrases (the secret backup words for a crypto wallet), or other sensitive information. This is a reminder that even if your crypto is stored securely on a hardware device, you should always be cautious about emails asking you to take action, and verify any requests through official websites or apps directly.

Brevo, formerly known as Sendinblue, is a widely used email marketing and customer relationship management platform. According to reports, a login flaw in Brevo's system was exploited by attackers who then used the platform's infrastructure to distribute phishing emails to subscribers of several cryptocurrency-related services, most notably Trezor, a popular hardware wallet manufacturer.

Read the full analysis with a CryptoBipto membership

Members can read the full analysis of every story, not just the headline.

Get started

SOURCES

  • cointelegraph.com

RELATED

PhishingHardware WalletsEmail SecurityThird-Party Risk