NewsTradingSentimentCalendarCommunityBriefing
Markets

138 Brevo Accounts Breached in Crypto Phishing Attack

By Markets Desk · 2026-09-11 · 1 min read
A physical hardware wallet device sits on a desk next to a computer keyboard.
Illustration: Tradingbird

An attacker exploited a flaw in Brevo to access 138 customer accounts, triggering a supply-chain phishing campaign against crypto users.

An attacker exploited a security flaw in the email marketing platform Brevo to access 138 customer accounts. This breach enabled a targeted phishing campaign against subscribers of cryptocurrency companies.

Six of the compromised accounts were used to send malicious emails to stored contact lists. Attackers also exported contact data from 43 other accounts, leaving 93 accounts with no significant activity. GN markets/crypto (en-US) reports that the incident targeted firms in the crypto sector.

Major crypto firms confirm breach impact

Trezor, CoinTracking, and BitBox confirmed that their customers received phishing messages. Trezor warned its 347,000 newsletter subscribers about the third-party security incident. The emails were sent from legitimate company domains, increasing their credibility.

The malicious messages contained links designed to trick users into downloading unauthorized applications. Recipients were prompted to enter their wallet backup information. CoinTracking reported a similar tactic involving requests to refresh API keys.

Phishing emails mimic hardware vulnerabilities

One phishing email claimed a critical hardware bug in Trezor devices. It alleged that STM32 microcontrollers suffered from insufficient randomness in recovery phrase generation. The message stated that seeds had as little as 40 bits of entropy.

Trezor advised users to move funds to a new wallet if they entered their backup. The company emphasized that no legitimate entity requests recovery phrases via email. Users are urged to verify security alerts through official channels before acting.

Security guidance for affected users

Users should avoid installing apps through links in unsolicited emails. Reputable companies do not ask for login details or API keys via email. Checking the official website for security notices is a recommended verification step.

Malwarebytes suggests using its Scam Guard tool to analyze suspicious messages. This tool helps users identify potential scams and provides guidance on next steps. Vigilance is required as contacts from the 43 breached accounts remain at risk.

Based on reporting by Malwarebytes, compiled by the Tradingbird desk.

More from the Markets desk

All desk stories