September 26, 2026
Email marketing platform breach used to phish crypto wallet customers

What happened
Brevo, an email marketing platform used by several cryptocurrency companies to manage newsletters, disclosed a breach in which an attacker exploited a flaw in its SAML SSO authentication to gain unauthorized access to customer accounts. According to Malwarebytes, Brevo identified the incident on September 10, and a subsequent postmortem found 138 compromised accounts — six of which were used to send phishing emails directly to those companies' own subscriber lists, with 43 more having contact data exported.
Who was targeted
Three cryptocurrency firms confirmed their Brevo accounts were abused in the campaign: hardware wallet makers Trezor and BitBox, and portfolio-tracking service CoinTracking. Trezor alone has roughly 347,000 newsletter subscribers, all of whom were potential recipients of the fraudulent messages.
How the phishing emails worked
The messages were built to look like routine security notices from trusted vendors. The Trezor-branded email carried the subject "Critical Security Alert: STM32 Entropy Bug Identified" and claimed a hardware flaw required recipients to back up their recovery phrase through a linked page — a request no legitimate hardware wallet vendor would ever make by email. The CoinTracking-branded version, titled "Data Breach Notice," pushed recipients to refresh API keys through a malicious link.
Why it matters
Because the emails came from the real newsletter infrastructure of trusted brands, they would have passed the sender-reputation checks that many users rely on to judge legitimacy. This is a supply-chain phishing pattern: compromising a third-party vendor to reach an already-trusting audience, rather than attacking the wallet or exchange directly. A seed phrase should never be entered anywhere in response to an email, regardless of how official the message looks — no hardware wallet manufacturer needs it to fix a hardware bug.
What to do
Malwarebytes advises verifying any urgent security claim through a vendor's official app or website rather than a link in an email, never downloading software from an emailed link, and never entering a recovery phrase into a web form under any circumstance. If you've already reused a phrase or key you're unsure about, treating it as compromised and moving funds to a newly generated wallet is the safer default.
— WalletRecover Team
Source: Malwarebytes