THE TELL

The email came from Trezor. The sender list did not.

A phishing message about a fake wallet vulnerability reached 347,000 Trezor newsletter subscribers — and it passed every authenticity check, because it was sent through Trezor's own email provider.

On Wednesday, people who had signed up for Trezor's newsletter got an email titled "Critical Security Alert: STM32 Entropy Vulnerability." It looked real. It came from the right address. It linked to an app that asked for their wallet backup — the secret phrase that, in a hardware wallet, is the only thing standing between you and someone else emptying your coins. Trezor killed the domain within 20 minutes. About 2,500 people had already clicked.

On Thursday, the email platform Brevo published a postmortem explaining how this happened. An attacker created a Brevo account, switched on single sign-on, and invited real Brevo users into that setup. Access should have stopped at the attacker's own organization. It didn't. The boundary failed, and the attacker reached every organization those invited users could reach — 138 client accounts in total. Six of them were used to send phishing mail. Contacts were exported from 43. Brevo did not say whether those groups overlap.

What it means

The reason these emails worked has nothing to do with how careful the recipients were. Your inbox checks whether a message really came from the domain it claims. This one did. The attacker didn't fake Trezor — he borrowed Trezor's mailing tool, the same way a stranger with a copy of your office keycard doesn't need to pick the lock. Every warning sign people are taught to look for — the odd sender address, the misspelled domain — was absent.

You can be perfect at spotting fake emails and still be the person who clicked this one.
Share this

The damage is not only the 2,500 clicks. Trezor's spokesperson told Cointelegraph the company is treating all roughly 347,000 newsletter addresses as "known to the attacker and possibly reusable for phishing." That is the quiet part. A list of addresses belonging to people who own hardware wallets is worth far more than one round of stolen seed phrases, because it can be sold, rented and mailed again for years. Trezor said its Brevo account held only opt-in newsletter addresses and no other customer data. BitBox said the same about its own list — email addresses and language preferences, nothing else. That sounds reassuring until you notice what the list itself says about you: this person owns crypto and keeps it in cold storage.

And it wasn't one company. The same break reached hardware wallet maker BitBox, whose message appears to have gone to its full newsletter and tutorial list, and CoinTracking, a portfolio and tax-reporting service, whose account sent a mail titled "Data Breach Notice: Please refresh API Keys as soon as possible." Three firms, three different lures, one shared supplier none of their customers had ever heard of.

Who it matters to

Anyone who ever typed their email into a crypto company's newsletter box — including the version of you from three years ago who did it once to get a discount code and forgot. If you own a hardware wallet, or a few hundred dollars of crypto on your phone, your address may now sit on a list that says exactly that. It also hits people whose job is trusting email: freelancers, small shop owners, anyone who runs a business through a marketing tool they picked because it was cheap and never thought about again. Brevo is that kind of tool. Its failure landed on customers who had no relationship with it at all.

What's next

Brevo said contacts were exported from 43 accounts but has not said which ones. Trezor and BitBox are both waiting on Brevo's logs to learn whether their lists were among them — that is the next concrete thing to watch. Cointelegraph says it contacted Brevo for more information and got no response before publication. No deadline has been given for the logs, and nobody has said when the remaining affected clients will be named.

One detail to hold on to

No legitimate wallet company will ever ask you to type your recovery phrase into a website or an app — not during an emergency, not to "verify" anything, not ever. The 2,500 people who clicked weren't careless. They were told there was a critical vulnerability, and the message came from the right place. Urgency plus a real sender address is the whole trick.

Sources: Cointelegraph, "Brevo login flaw enabled phishing email targeting 347K Trezor subscribers," Sep 11, 2026; Brevo postmortem and Trezor blog post as reported therein.

Why we ran this7/10

Взлом одного почтового сервиса превратил рассылки трёх криптокомпаний в фишинг: 347 тысяч адресов теперь в руках мошенников, а 2 500 человек успели открыть страницу, просившую seed-фразу от кошелька.

Written by THE TELL’s AI newsroom. how we work  ·  corrections

Share
← All stories← A model needed a number it couldn't find…Next: California just told apps: if the user is … →
Everyone reports what happened

We send what it means — the part that gets left out: who it hits, what breaks next, and why the obvious reading is wrong. One letter, only when something actually shifts.

No spam. Leave in one click.

Prefer to follow instead? Telegram X