AN attacker breached Brevo, a third‑party email marketing platform used by several cryptocurrency companies, and conducted a supply‑chain phishing campaign aimed at newsletter subscribers. Brevo later confirmed that 138 customer accounts were accessed in a postmortem, with six of those accounts used to send phishing emails, 43 accounts exporting contacts, and 93 accounts showing no meaningful activity.
The targeted campaigns affected subscribers of prominent crypto firms, including Trezor, CoinTracking and BitBox, with phishing emails circulating to their newsletters. Trezor warned its roughly 347,000 subscribers that a security incident at a third‑party provider had enabled a large phishing operation.
One phishing lure from the attackers imitated a hardware‑wallet alert, titled “Critical Security Alert: STM32 Entropy Bug Identified,” which claimed a hardware‑level vulnerability in STM32 microcontrollers and suggested a defective device population, potentially exposing seeds and enabling brute‑force attacks. CoinTracking also reported a message titled “Data Breach Notice: Please refresh API Keys as soon as possible,” containing a malicious link. Exact figures for how many recipients clicked or were compromised are not disclosed.
The emails appeared to come from legitimate domains, making them convincing and difficult to recognise as phishing. The article notes that the attackers exported contacts from 43 Brevo accounts, which could enable further targeted campaigns.
In practical terms, recipients are advised to verify security notices via official channels, avoid installing apps from unsolicited links, never enter wallet recovery phrases outside a physical device, and recognise that reputable firms will not request recovery phrases, API keys, or login details by email. If a link is followed or sensitive data entered, affected users should contact the provider directly for guidance and consider moving funds to a new wallet where appropriate.