Close Menu
FSNN | Free Speech News NetworkFSNN | Free Speech News Network
  • Home
  • News
    • Politics
    • Legal & Courts
    • Tech & Big Tech
    • Campus & Education
    • Media & Culture
    • Global Free Speech
  • Opinions
    • Debates
  • Video/Live
  • Community
  • Freedom Index
  • About
    • Mission
    • Contact
    • Support
Trending

I Went Looking for a Libertarian Miracle in Argentina. I Found Something Messier.

7 minutes ago

India starts tokenizing $620 billion corporate bond market with digital rupee settlement

31 minutes ago

Why Postliberalism Failed–And Is Likely to Fail Again

1 hour ago
Facebook X (Twitter) Instagram
Facebook X (Twitter) Discord Telegram
FSNN | Free Speech News NetworkFSNN | Free Speech News Network
Market Data Newsletter
Friday, September 11
  • Home
  • News
    • Politics
    • Legal & Courts
    • Tech & Big Tech
    • Campus & Education
    • Media & Culture
    • Global Free Speech
  • Opinions
    • Debates
  • Video/Live
  • Community
  • Freedom Index
  • About
    • Mission
    • Contact
    • Support
FSNN | Free Speech News NetworkFSNN | Free Speech News Network
Home»Cryptocurrency & Free Speech Finance»Brevo Login Breach Affected Trezor, BitBox and CoinTracking
Cryptocurrency & Free Speech Finance

Brevo Login Breach Affected Trezor, BitBox and CoinTracking

News RoomBy News Room2 hours agoNo Comments2 Mins Read1 Views
Share Facebook Twitter Pinterest Copy Link LinkedIn Tumblr Email VKontakte Telegram
Brevo Login Breach Affected Trezor, BitBox and CoinTracking
Share
Facebook Twitter Pinterest Email Copy Link

Listen to the article

0:00
0:00

Key Takeaways

Playback Speed

Select a Voice

An attacker exploited a flaw in email platform Brevo’s login system to access 138 client accounts, enabling a phishing email to reach roughly 347,000 Trezor newsletter subscribers and similar fraudulent messages to be distributed through accounts belonging to hardware wallet maker BitBox and crypto portfolio tracking and tax-reporting platform CoinTracking.

In a Thursday postmortem, Brevo said six accounts were used to send phishing emails, contacts were exported from 43 and 93 accounts showed no meaningful activity. The platform did not specify whether the categories overlapped. 

The attacker created a Brevo account, enabled single sign-on and invited legitimate Brevo users into the configuration. Brevo said access should have been confined to that organization, but an authorization boundary failed and granted access to every organization the invited users could reach.

The disclosure expands on warnings issued by Trezor and BitBox on Wednesday, identifying their shared provider and explaining why the emails passed normal authentication checks and appeared genuine. 

Cointelegraph reached out to Brevo for more information but did not receive a response before publication. 

Crypto firms assess potential subscriber exposure 

In a blog post, Trezor said the phishing message, titled “Critical Security Alert: STM32 Entropy Vulnerability,” contained a link to an app that requested users’ wallet backups. The company disabled the domain at the DNS level within 20 minutes, but about 2,500 people accessed the link before the takedown.

A Trezor spokesperson told Cointelegraph that “the initial email was sent to 347,000 customers,” all of whom were subsequently contacted about the risk. The company’s Brevo account stored only opt-in newsletter email addresses and no other customer data.

“Until we hear more from Brevo, we are treating all roughly 347,000 newsletter addresses as known to the attacker and possibly reusable for phishing,” the spokesperson said.

Related: Liquid Network resumes block production after $320M exploit

A BitBox spokesperson told Cointelegraph that its unauthorized email was sent through Brevo and appeared to have reached its full newsletter and tutorial list. 

BitBox said Brevo held only email addresses and language preferences. It found no evidence of compromised company credentials, downloaded contacts, lost funds or disclosed recovery phrases, but is treating the list as potentially accessed while awaiting Brevo’s logs.

Meanwhile, CoinTracking said its Brevo account distributed an email titled “Data Breach Notice: Please refresh API Keys as soon as possible.” It warned recipients not to follow the email’s links.

Magazine: 10 of the greatest unsolved crypto mysteries

Read the full article here

Fact Checker

Verify the accuracy of this article using AI-powered analysis and real-time sources.

Get Your Fact Check Report

Enter your email to receive detailed fact-checking analysis

5 free reports remaining

Continue with Full Access

You've used your 5 free reports. Sign up for unlimited access!

Already have an account? Sign in here

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Telegram Copy Link
News Room
  • Website
  • Facebook
  • X (Twitter)
  • Instagram
  • LinkedIn

The FSNN News Room is the voice of our in-house journalists, editors, and researchers. We deliver timely, unbiased reporting at the crossroads of finance, cryptocurrency, and global politics, providing clear, fact-driven analysis free from agendas.

Related Articles

Cryptocurrency & Free Speech Finance

India starts tokenizing $620 billion corporate bond market with digital rupee settlement

31 minutes ago
Cryptocurrency & Free Speech Finance

Bitcoin below $77,000, Zcash leads losses as traders bet on a Fed rate hike

2 hours ago
Cryptocurrency & Free Speech Finance

Bitcoin traders dial down bullish plays ahead of U.S. inflation data

3 hours ago
Cryptocurrency & Free Speech Finance

Crypto exchange giant Bybit to offer European ‘super-app’ with stocks, derivatives

4 hours ago
Cryptocurrency & Free Speech Finance

Treasury yields continue to rise even as Bessent doubles down on bond buybacks

5 hours ago
Cryptocurrency & Free Speech Finance

Arya.ag Tests Tokenized Grain Ownership Records on Avalanche

5 hours ago
Add A Comment
Leave A Reply Cancel Reply

Editors Picks

India starts tokenizing $620 billion corporate bond market with digital rupee settlement

31 minutes ago

Why Postliberalism Failed–And Is Likely to Fail Again

1 hour ago

Bitcoin below $77,000, Zcash leads losses as traders bet on a Fed rate hike

2 hours ago

Brevo Login Breach Affected Trezor, BitBox and CoinTracking

2 hours ago
Latest Posts

Marijuana Contracts Are Not Enforceable in Federal Court

2 hours ago

CPJ, partners call Pakistan’s prime minister to address alarming deterioration in press freedom

2 hours ago

Bitcoin traders dial down bullish plays ahead of U.S. inflation data

3 hours ago

Subscribe to News

Get the latest news and updates directly to your inbox.

At FSNN – Free Speech News Network, we deliver unfiltered reporting and in-depth analysis on the stories that matter most. From breaking headlines to global perspectives, our mission is to keep you informed, empowered, and connected.

FSNN.net is owned and operated by GlobalBoost Media
, an independent media organization dedicated to advancing transparency, free expression, and factual journalism across the digital landscape.

Facebook X (Twitter) Discord Telegram
Latest News

I Went Looking for a Libertarian Miracle in Argentina. I Found Something Messier.

7 minutes ago

India starts tokenizing $620 billion corporate bond market with digital rupee settlement

31 minutes ago

Why Postliberalism Failed–And Is Likely to Fail Again

1 hour ago

Subscribe to Updates

Get the latest news and updates directly to your inbox.

© 2026 GlobalBoost Media. All Rights Reserved.
  • Privacy Policy
  • Terms of Service
  • Our Authors
  • Contact

Type above and press Enter to search. Press Esc to cancel.

🍪

Cookies

We and our selected partners wish to use cookies to collect information about you for functional purposes and statistical marketing. You may not give us your consent for certain purposes by selecting an option and you can withdraw your consent at any time via the cookie icon.

Cookie Preferences

Manage Cookies

Cookies are small text that can be used by websites to make the user experience more efficient. The law states that we may store cookies on your device if they are strictly necessary for the operation of this site. For all other types of cookies, we need your permission. This site uses various types of cookies. Some cookies are placed by third party services that appear on our pages.

Your permission applies to the following domains:

  • https://fsnn.net
Necessary
Necessary cookies help make a website usable by enabling basic functions like page navigation and access to secure areas of the website. The website cannot function properly without these cookies.
Statistic
Statistic cookies help website owners to understand how visitors interact with websites by collecting and reporting information anonymously.
Preferences
Preference cookies enable a website to remember information that changes the way the website behaves or looks, like your preferred language or the region that you are in.
Marketing
Marketing cookies are used to track visitors across websites. The intention is to display ads that are relevant and engaging for the individual user and thereby more valuable for publishers and third party advertisers.