Major Phishing Campaign Exploits Email Platform Flaw, Targeting Hundreds of Thousands of Crypto Users
A security incident leveraging a vulnerability in email service Brevo compromised cryptocurrency platforms and reached roughly 347,000 subscribers with phishing messages.
Widespread Phishing Attack Emerges from Email Platform Compromise
Cryptocurrency platforms this week confirmed a coordinated phishing campaign that exploited a critical flaw in Brevo, an email service provider. The attack reached approximately 347,000 newsletter subscribers at Trezor, a leading hardware wallet manufacturer, while similar fraudulent messages were distributed through compromised accounts belonging to BitBox and CoinTracking. The incident demonstrates how vulnerabilities in infrastructure services can cascade across the entire cryptocurrency ecosystem, exposing even security-conscious users to sophisticated threats.
Technical Details of the Attack Vector
According to Brevo’s postmortem disclosure, the attacker’s approach was methodical and exploited a fundamental gap in the platform’s access controls. The threat actor established a Brevo account, configured single sign-on functionality, and invited existing legitimate users into the setup. Here, a critical failure occurred: Brevo’s authorization system intended to restrict access to only the newly created organization but instead granted the invited users access to every organization they maintained connections with across the platform. This architectural flaw permitted the attacker to compromise 138 distinct client accounts. The attacker sent phishing emails using six of these compromised accounts, exported contact databases from 43 additional accounts, and identified 93 accounts that appeared inactive.
The phishing emails proved particularly dangerous because they originated from legitimate, authenticated company accounts. For Trezor users specifically, the malicious message arrived bearing the subject “Critical Security Alert: STM32 Entropy Vulnerability” and contained a link directing users to submit their wallet backup files. Trezor responded with impressive speed, neutralizing the threat by disabling the malicious domain at the DNS level within 20 minutes. However, the window of exposure had already allowed approximately 2,500 users to access the link before it went offline.
Implications for Cryptocurrency Security and User Safety
The incident underscores a fundamental challenge facing the cryptocurrency industry: security depends not only on the strength of blockchain protocols and hardware wallets but also on the reliability of supporting infrastructure. Despite hardware wallets’ reputation for security, users remain vulnerable when third-party service providers experience breaches. Trezor confirmed that its Brevo account contained exclusively opt-in newsletter email addresses, without customer data, recovery information, or transaction records. BitBox and CoinTracking made similar assurances regarding the limited data stored on their respective Brevo accounts—email addresses and minimal user preferences only.
Both companies acknowledged they are treating their email subscriber lists as potentially compromised while awaiting detailed forensic logs from Brevo. This conservative approach reflects industry best practices during security incidents and encourages users to remain vigilant for phishing attempts. The broader takeaway emphasizes the critical importance of robust authorization controls, thorough security audits, and rapid incident response protocols for any service provider supporting cryptocurrency platforms. For the wider crypto market, this incident reinforces why users must exercise caution with email communications claiming to be from their service providers, regardless of apparent legitimacy.
Source: Brevo, via Cointelegraph. Not financial advice.