Attackers abused access to Brevo (an email marketing platform) to send highly convincing phishing emails from legitimate cryptocurrency company domains to newsletter subscribers. The lures claimed urgent security issues (hardware vulnerability or data breach) and pushed victims to click links, download an app, and provide sensitive wallet/API information.
How the attack worked
Attackers gained access to Brevo, an email marketing platform used by several cryptocurrency companies and other firms, by exploiting its SAML SSO handling. This gave them access to 138 customer accounts. Six of those accounts were used to send phishing emails, and contacts were exported from 43 accounts. Because the emails went out through the legitimate domains of trusted companies like Trezor and CoinTracking, they bypassed the usual skepticism that unfamiliar senders would trigger.
The lures used
Trezor subscribers received an email with the subject "Critical Security Alert: STM32 Entropy Bug Identified" and a subtitle warning of an urgent hardware microcontroller vulnerability. The message pushed recipients to click a link, download an app, and enter their wallet backup or recovery information, an extremely sensitive piece of data that gives full control over a crypto wallet.
CoinTracking customers received a different lure, a "Data Breach Notice" urging them to refresh their API keys as soon as possible, again through a malicious link. Both messages relied on urgency and a plausible security-related premise to get victims moving quickly instead of pausing to verify.
Why it succeeded
This was a supply-chain phishing campaign carried out through a third-party vendor rather than a direct compromise of Trezor or CoinTracking themselves. Because the emails came from real company domains and mimicked routine security notifications, recipients had little reason for immediate suspicion. It can be difficult to recognize a phishing email when it comes from a legitimate company domain and looks convincing, which is exactly the gap this campaign exploited.
What to watch for
- Unexpected, urgent security alerts pushing immediate action, especially around hardware vulnerabilities or data breaches
- Emails asking you to download an app through a link rather than an official app store or the vendor's known site
- Any request to enter a wallet recovery phrase, seed backup, API key, or login credential in response to an email
Building resistance
Organizations and individuals handling crypto assets should verify urgent security alerts through the company's official website or app rather than trusting a link in an email. Apps should never be installed from links in unsolicited messages, no matter how urgent the claim. Recovery phrases should never be entered anywhere other than on the physical hardware device, and reputable companies will not ask for recovery phrases, API keys, or login details by email. Since this incident shows that trusted domains can still deliver phishing when a vendor is compromised, treating a familiar sender as sufficient proof of legitimacy is no longer a safe assumption.
Key findings
- Attackers exploited Brevo’s SAML SSO handling to access 138 customer accounts; 6 were used to send phishing emails and contacts were exported from 43 accounts.
- Phishing was delivered through legitimate company domains and targeted newsletter subscribers in the crypto ecosystem.
- Trezor subscribers received an email with the subject “Critical Security Alert: STM32 Entropy Bug Identified” urging action related to a supposed hardware vulnerability.
- The Trezor lure pushed recipients to click a link, download an app, and enter their wallet backup/recovery information.
- CoinTracking customers received a “Data Breach Notice” themed message urging them to “refresh API Keys as soon as possible,” also with a malicious link.
Who’s being targeted
- Commonly targeted roles: Finance, Treasury / Crypto asset custodians, Executive assistants supporting finance leadership, IT / Security awareness audience (all staff), Customer support teams handling security inquiries.
- Affected industries: Cryptocurrency, Financial services, Technology / SaaS (email marketing).
- Attack channels: email, website.
- Impersonated: Trezor (hardware wallet company), CoinTracking.
Red flags to watch for
- Unexpected urgent security alert pushing immediate action
- Link prompts app download from an email
- Request to enter wallet backup/recovery phrase (highly sensitive)
- Creates urgency around a supposed breach
- Includes a link to take immediate action
- Asks for sensitive authentication material (API keys) via an email-driven workflow
Frequently asked questions
How did attackers access legitimate crypto company email domains?
Attackers exploited Brevo's SAML SSO handling to access 138 customer accounts, using 6 of them to send phishing emails and exporting contacts from 43 accounts.
What made these phishing emails hard to detect?
The phishing emails were delivered through legitimate company domains, which made them look convincing since it can be difficult to recognize phishing when it comes from a domain you already trust.
What did the Trezor phishing email ask victims to do?
It urged recipients to click a link, download an app, and enter their wallet backup or recovery phrase, framed as an urgent fix for a supposed hardware microcontroller vulnerability.
What should users do if they get an urgent security email from a vendor?
Verify the claim through the company's official website or app rather than clicking the link in the email, and never enter a recovery phrase anywhere other than on the physical device.
Read the video transcript
You get an email from Trezor or CoinTracking, sent from their real domain, screaming: “Critical Security Alert” or “Data Breach Notice.” Attackers abused Brevo’s SAML SSO to get into 138 marketing accounts, then used six real crypto company senders to blast phishing to newsletter subscribers like you. The Trezor email pushes a link to download an app and enter your wallet backup. The CoinTracking one urges you to click and “refresh API Keys.” Both are after your recovery phrase or API keys. Here’s the rule: if an email claims an urgent crypto security issue, don’t click anything, open the official site or app yourself and check for alerts there.