
Brevo Exploit Leads to Phishing Attack on Trezor, BitBox, and CoinTracking Users
Vexoda Newsroom
A security vulnerability in Brevo's login system allowed an attacker to send phishing emails to nearly 347,000 Trezor subscribers and similar fraudulent messages to users of BitBox and CoinTracking.
A significant security breach has impacted users of several prominent cryptocurrency services after an attacker exploited a flaw within the email marketing platform Brevo. This vulnerability enabled the perpetrator to gain access to 138 client accounts, facilitating the distribution of a phishing email campaign. This campaign specifically targeted approximately 347,000 subscribers of the hardware wallet manufacturer Trezor, and extended to similar fraudulent communications sent to users of BitBox, another hardware wallet provider, and CoinTracking, a crypto portfolio management tool.
The breach involved an attacker creating a new Brevo account and leveraging a single sign-on (SSO) feature to invite legitimate Brevo users. Despite Brevo's intended security protocols to confine access within specific organizations, an authorization boundary failure occurred. This error inadvertently granted the attacker broad access to a wider network of organizations connected to the invited users, leading to the compromise of accounts used to send the malicious emails and export contact lists.
Brevo's internal investigation revealed that six accounts were actively used to send the phishing emails, with contacts exported from an additional 43 accounts. While 93 accounts showed no significant activity, the platform has not specified whether these categories overlap, leaving the full extent of data access uncertain. The compromised accounts were used to send deceptive messages, with the attacker gaining access to user email addresses, which are now considered potentially reusable for future phishing attempts by the adversary.
Trezor confirmed that the phishing email, masquerading as a critical security alert regarding an "STM32 Entropy Vulnerability," directed recipients to a malicious application. This application illicitly requested users' sensitive wallet backup information. Although Trezor acted swiftly, disabling the malicious domain at the DNS level within 20 minutes, an estimated 2,500 individuals had already clicked the link before the takedown occurred. All affected subscribers were subsequently notified of the potential risk.
The implications of this breach extend beyond the immediate phishing attempt. For Trezor, BitBox, and CoinTracking, the exposure of subscriber email lists means that all 347,000 Trezor newsletter recipients, and potentially similar lists from the other services, must be treated as compromised. This necessitates heightened vigilance from users and underscores the critical importance of secure email platform infrastructure, as even a single provider's vulnerability can cascade across multiple trusted services within the crypto ecosystem.
Looking ahead, users of Trezor, BitBox, and CoinTracking should maintain extreme caution regarding unsolicited communications, especially those requesting personal information or wallet backups. They should verify the legitimacy of any security alerts directly through official channels, not by clicking links in emails. For the affected platforms, ongoing monitoring of Brevo's security posture and communication regarding further mitigation strategies will be crucial. Traders should remain alert for any follow-up phishing attempts leveraging the compromised contact information.
Source: Cointelegraph. Summarized and rewritten by the Vexoda Newsroom. This is market news, not financial advice.