Skip to main content
AVOID.NET

Brevo (email marketing platform used by Trezor, BitBox, CoinTracking, Solana Mobile)

avoid.net/brevo-email-marketing-platform-used-by-trezor-bitbox-cointracking-solana-mobile32/100·85% conf.
[AI-DRAFTED · AWAITING VERIFICATION]

Auto-generated score, not yet verified against the scoring model. Under review — treat as indicative, not a verdict.

anchored·3kciyx…eJsL

Summary

Brevo, a Paris-based email marketing and CRM platform (formerly Sendinblue) used by numerous crypto companies for newsletters, suffered a SAML single sign-on (SSO) authorization flaw that an attacker exploited around September 9-10, 2026 to access 138 customer accounts. Six of those accounts, including ones belonging to hardware wallet maker Trezor, hardware wallet maker BitBox, and portfolio tracker CoinTracking, were used to send convincing phishing emails to hundreds of thousands of real subscribers from the companies' legitimate domains, prompting some recipients to enter sensitive wallet information. Brevo says it closed the access path and issued a fix within hours, but the incident is a documented supply-chain risk for any crypto business or user relying on Brevo-delivered newsletters.

Connected Entities

1 entities
Tokens
Brevo (email marketing platform used by Trezor, BitBox, CoinTracking, Solana Mobile)
Relationships
    Have evidence about Brevo (email marketing platform used by Trezor, BitBox, CoinTracking, Solana Mobile)?

    Timeline(6 events)

    9 September 2026

    Trezor states, in its own official blog post, that Brevo suffered the security incident affecting 120 Brevo accounts (later revised by Brevo to 138).

    Trezor official blog

    September 2026

    An attacker creates a Brevo account, enables SAML SSO on it, and invites legitimate Brevo customer accounts into that configuration, exploiting an authorization-scoping flaw to gain access to 138 customer accounts without needing their passwords.

    SecurityWeek / Cointelegraph reporting on Brevo's postmortem

    September 2026

    Phishing emails are sent from 6 compromised Brevo accounts, including Trezor's, BitBox's, and CoinTracking's, to their real subscriber lists; Trezor's email (subject referencing an 'STM32 Entropy' vulnerability) reaches roughly 347,000 addresses. The malicious site is taken down at the DNS level roughly 20 minutes after detection, by which point about 2,500 recipients had clicked the link.

    Trezor official blog / Cointelegraph

    10 September 2026

    Brevo marks the incident "Resolved" on its public status page, stating the issue has been resolved and all affected services are functioning normally.

    Brevo Status page

    September 2026

    Brevo posts a public statement on X confirming an attacker accessed 120 (later revised to 138) customer accounts and used the access to send phishing emails; Brevo states the unauthorized access was closed as of 11:30 AM CEST.

    Brevo official X account

    September 2026

    Trezor, BitBox, and CoinTracking publicly warn customers of the phishing emails; mainstream outlets including TechCrunch, SecurityWeek, BleepingComputer, and Cointelegraph report on the breach and its impact on crypto users. Solana Mobile also issues a precautionary phishing warning to its users.

    TechCrunch
    Provenance & Audit Trail

    Decision Log

    This investigation is cryptographically anchored to the Solana blockchain (1 event). 10 of 11 cited source URLs have an Internet Archive snapshot.

    model: claude-code-investigator

    generated: 9/12/2026, 5:38:10 PM

    last updated: 9/12/2026, 9:17:00 PM

    avoid.net — verified advice for a post-truth world