NewsTradingSentimentCalendarCommunityBriefing
Markets

Phishing wave hits crypto users after email provider breach

By Markets Desk · 2026-09-10 · 1 min read
A digital padlock floating in a dark void with glitching data streams
Illustration: Tradingbird

Thousands of crypto wallets faced phishing attempts after a breach at email provider Brevo. The attack exploited 120 compromised accounts to send malicious messages.

Thousands of cryptocurrency holders received phishing emails on Wednesday. The messages originated from a breach at email provider Brevo. Trezor, CoinTracking, and BitBox confirmed their customer bases were targeted. The attackers used legitimate company domains to send the alerts.

Brevo stated an attacker accessed 120 customer accounts. The company closed the access point on Thursday. It promised a full post mortem later. The firm raised over $580 million in December to expand its operations.

Attackers targeted multiple crypto firms

Trezor received emails titled Critical Security Alert. The messages urged users to click links to fix alleged issues. BitBox noted that multiple firms share the same newsletter provider. CoinTracking reported emails asking users to refresh API keys.

Users reported the emails looked highly legitimate. Several clicked links before landing on fake sites. Trezor stated it did not send the messages. The company took down the malicious domain.

Security risks remain elevated

Trezor recently suffered a breach exposing 81,000 customer details. That incident involved its shipping and logistics provider. Customers also reported receiving malicious QR codes by post. Prosecutors note criminals use stolen lists to rank targets.

Wrench attacks on crypto owners increased 33 percent year over year. Losses reached $124 million so far this year. This compares to $10.5 million in the first half of 2025. Recent incidents include the death of an investor in Paraguay.

Companies advise users to act

BitBox sent a warning to all subscribers. The firm reported the phishing domains to authorities. Most malicious links have been taken down. Trezor advised users not to click any links. GN markets/crypto (en-US) reported these developments.

Based on reporting by GN markets/crypto (en-US), compiled by the Tradingbird desk.

More from the Markets desk

All desk stories