Brevo, the email delivery platform whose infrastructure was used to send last week's phishing emails impersonating Trezor and BitBox, has published a post-mortem identifying the root cause: an authorization flaw in its login system that let an attacker reach 138 customer accounts — including those used by Trezor, BitBox and crypto tax-reporting service CoinTracking.
The disclosure closes the loop on the question of how fraudulent messages were sent from addresses that passed every standard email-authentication check. The answer was not spoofing. The attacker was inside the senders' own platform.
How the Authorization Boundary Failed
According to Brevo's incident write-up, the attacker first created a Brevo account and enabled single sign-on, then invited legitimate Brevo users into the new, attacker-controlled organization.
At that point, access should have remained confined to the attacker's organization. Instead, Brevo said a permission boundary failed: users who belonged to more than one organization effectively opened the door to all of them. The attacker gained access to every organization those invited users could reach.
The blast radius was uneven across the 138 affected accounts. Six were used to send phishing emails. Contact lists were exported from 43 accounts, potentially arming the attacker with verified address lists usable outside Brevo's infrastructure. Brevo recorded no meaningful activity across another 93 accounts, and did not specify whether the groups overlapped.
Trezor: 347,000 Addresses, 2,500 Clicks, 20 Minutes
Trezor's account contained roughly 347,000 opt-in newsletter email addresses and no other customer data, the company said. A spokesperson told Cointelegraph the initial phishing message — titled "Critical Security Alert: STM32 Entropy Vulnerability" — was sent to all of them, and that the same subscriber list was then used to distribute the warning about the attack itself.
The message pushed recipients toward a malicious application that requested wallet recovery phrases, the one piece of data from which full theft follows. Trezor said it took the malicious domain offline at the DNS level within 20 minutes. Around 2,500 people had accessed the link before the takedown.
"Until we hear more from Brevo, we are treating all roughly 347,000 newsletter addresses as known to the attacker and possibly reusable for phishing," the spokesperson said. The company confirmed that its hardware wallets, wallet backups and internal systems were not compromised, and that customers who did not enter their recovery phrase into the malicious application remain safe.
BitBox had identified a parallel campaign on Wednesday, noting that several Bitcoin companies appeared to have been targeted through a shared newsletter provider — now identified as Brevo. CoinTracking customers received a different lure built around that platform's function: a "Data Breach Notice: Please refresh API Keys as soon as possible" email designed to harvest exchange API credentials.
The Pattern: Vendors as the Perimeter
The incident is the third this year in which a third party, rather than Trezor itself, was the point of failure. In August, a breach at logistics provider ShipMonk exposed records belonging to roughly 14,000 customers, later expanded by approximately 67,000 US customer records from 2019–2021 purchases. Attackers have now held verified lists of hardware wallet customers and newsletter subscribers — precisely the audience best targeted by fake security advisories.
The technical lesson from Brevo's post-mortem is narrower and harsher: an email platform's multi-organization permission model became a single point of compromise across dozens of unrelated customers. The operational lesson for users remains unchanged — verify security advisories on the vendor's official website, never through links in email, and no legitimate vendor asks for a recovery phrase.
TrustGrade covers the security and trust ecosystem around digital assets. For verified trust data on the platforms and firms shaping it, see trustgrade.ai.