BlocktoBlockto
Email Platform Breach Exposes 347,000 Trezor Subscribers to Phishing Attack
NEWS

Photo: Illustrative

Email Platform Breach Exposes 347,000 Trezor Subscribers to Phishing Attack

A security flaw in email marketing platform Brevo allowed an attacker to gain access to 138 client accounts, resulting in phishing emails being sent to roughly 347,000 subscribers of hardware wallet maker Trezor. Similar fraudulent messages were also distributed through accounts belonging to wallet maker BitBox and portfolio tracking platform CoinTracking.

Tristan R.
By Tristan R.

Senior Author · September 11, 2026

2 min
Key takeaways
A security flaw in email marketing platform Brevo allowed an attacker to gain access to 138 client accounts, resulting in phishing emails being sent to roughly 347,000 subscribers of hardware wallet maker Trezor.
Similar fraudulent messages were also distributed through accounts belonging to wallet maker BitBox and portfolio tracking platform CoinTracking.
According to Brevo's internal review, six compromised accounts were actually used to send phishing messages, while contact data was extracted from dozens of others.

A security flaw in email marketing platform Brevo allowed an attacker to gain access to 138 client accounts, resulting in phishing emails being sent to roughly 347,000 subscribers of hardware wallet maker Trezor. Similar fraudulent messages were also distributed through accounts belonging to wallet maker BitBox and portfolio tracking platform CoinTracking.

According to Brevo’s internal review, six compromised accounts were actually used to send phishing messages, while contact data was extracted from dozens of others. The attacker reportedly created a Brevo account, enabled single sign-on access, and invited legitimate users into a shared configuration. A failure in access controls allowed that account to reach far beyond its intended scope.

Trezor Moves Quickly to Contain Damage

The phishing email, disguised as a security alert, directed recipients to a fraudulent app requesting wallet backup information. Trezor disabled the malicious domain within 20 minutes, though roughly 2,500 people had already clicked the link. The company confirmed all affected subscribers were notified and said only opt-in email addresses were stored on the platform, with no other customer data exposed.

Other Firms Report Similar Incidents

BitBox confirmed its newsletter list was also affected, though it found no evidence of stolen funds or exposed recovery phrases. CoinTracking issued a warning after a fraudulent breach notice was sent through its own Brevo account, urging users not to click any included links.

How markets are positioning

Live market reaction

🛢️WTI Crude
+3.4%
Gold
+1.8%
Bitcoin
-1.8%
$DXY
+0.6%

Disclaimer

This content is for informational purposes only and does not constitute financial, investment, or legal advice. Cryptocurrency trading involves risk and may result in financial loss.

Exclusive partner offer

Start trading
with BloFin today

Up to $500 sign-up bonus and zero-fee trading on your first 30 days.

Buy crypto now

You will be redirected to BloFin

Share article

About the author

Tristan R.
Tristan R.

8+ years covering crypto markets, macro, and geopolitics. Previously at Decrypt and CoinDesk. Focused on the intersection of digital assets and traditional finance.

Email Platform Breach Exposes 347,000 Trezor Subscribers to Phishing Attack — Blockto - Blockto