started · updated
Brevo security breach triggers phishing attacks on crypto firms
A security breach at the marketing platform Brevo has exposed multiple cryptocurrency-related companies to targeted phishing campaigns. Attackers exploited a flaw in Brevo’s SAML single sign-on system to gain unauthorized access to approximately 138 customer accounts, allowing them to export contact lists from 43 accounts.
Trezor reported that the breach affected information linked to roughly 347,000 subscribers. The attackers sent fraudulent emails with the subject line ‘Critical Security Alert: STM32 Entropy Vulnerability,’ claiming a hardware flaw in Trezor wallets could expose recovery seeds. Because the emails originated from Trezor’s legitimate Brevo-hosted infrastructure, they bypassed standard security protocols like SPF, DKIM, and DMARC.
Other companies, including Solana Mobile, BitBox, and CoinTracking, also reported being affected. Solana Mobile disabled its Brevo account upon discovering the unauthorized access and is investigating the scope of the incident. While the phishing attempts aimed to steal user login details via malicious links, there is currently no evidence that the internal firmware or seed generation mechanisms of the hardware wallets themselves were compromised.
Entities
BitBox · Brevo · CoinTracking · Solana Mobile · Trezor