← Trezor Email Provider Breach (Brevo, September 2026)1 decision on this page
Audit log
Every state-changing event for Trezor Email Provider Breach (Brevo, September 2026): moderation decisions on community submissions, plus corrections and updates from the news pipeline. URL-based decisions are designed to carry three independent witnesses — the original source, an Internet Archive snapshot, and a Solana memo signed by our publicly-disclosed publisher key. Archive coverage is still being backfilled, so each decision below reports its own snapshot status rather than assuming one exists.
- #1publishby system:backfill2026-09-18 17:10:30ZScore: ? → ? (no score change)anchoranchored
- chain
- ●mainnet-betaslot 448,146,989
- sig
5FUUADnBFvTV…FLDW76nTexplorer ↗- hash
Hu1G6PDPbKnS…dd5ENQKpsha256 → base58
verifying row…full verify ↗canonical bytes (25552 B) ▸
{"actor":"system:backfill","investigation_id":"b2d97eef-f3b5-4dcb-8128-ea66069d00b6","kind":"publish","page_slug":"trezor-email-provider-breach-brevo-september-2026","published_at":"2026-09-18T17:10:30.353Z","sequence_num":1,"snapshot":{"content_type":"investigation","entity_name":"Trezor Email Provider Breach (Brevo, September 2026)","sections":[{"content":"On September 9, 2026, an unidentified threat actor exploited a flaw in Brevo's SAML Single Sign-On (SSO) implementation to gain unauthorized access to 138 Brevo customer accounts. Of those, six accounts were used to send phishing emails to the contact lists stored within them, and 43 accounts had their contact lists silently exported. Brevo detected the intrusion at 6:30 AM UTC on September 10 and closed the access route by 8:30 AM UTC. Trezor, the Prague-based hardware wallet manufacturer, uses Brevo (formerly Sendinblue) for its marketing newsletter. The attacker used Trezor's Brevo account to distribute approximately 347,149 phishing emails to Trezor newsletter subscribers on September 9. BitBox and CoinTracking also confirmed their Brevo accounts were among those exploited, though neither reported confirmed fund losses from their user bases as a direct result of this campaign. Solana Mobile disclosed on September 12, 2026 that its marketing email account had similarly been accessed without authorization as part of the same Brevo incident.","heading":"Incident Overview","severity":"high","sources":[{"credibility":1,"name":"Security incident at Brevo, our third-party email provider | Trezor","type":"official","url":"https://trezor.io/blog/news/security-incident-at-brevo-our-third-party-email-provider"},{"credibility":2,"name":"Trezor: 347,000 users targeted in phishing attacks after Brevo breach — BleepingComputer","type":"news_article","url":"https://www.bleepingcomputer.com/news/security/trezor-347-000-users-targeted-in-phishing-attacks-after-brevo-breach/"},{"credibility":1,"name":"Attacker gained access to client accounts — Brevo Status incident write-up","type":"official","url":"https://status.brevo.com/incidents/pawbvhq8/write-up"},{"credibility":1,"name":"Scammers target hundreds of thousands of crypto owners after Trezor confirms data breach of email provider — TechCrunch","type":"news_article","url":"https://techcrunch.com/2026/09/11/scammers-target-hundreds-of-thousands-of-crypto-owners-after-trezor-confirms-data-breach-of-email-provider/"}]},{"content":"Brevo's post-incident write-up details the root cause as an access-control boundary that was not enforced in its SAML SSO implementation. The attacker registered a new Brevo account, enabled SSO on it, and invited legitimate Brevo users into that SSO configuration. By controlling the identity provider in this setup, the attacker could authenticate as those invited users. Critically, when a user authenticated through this attacker-controlled SSO flow, Brevo's access-scoping logic failed to restrict that session to the attacker's single organization. Instead, the session carried permissions for all organizations that the invited user's own account could reach — including Brevo client accounts belonging to Trezor, BitBox, CoinTracking, Solana Mobile, and others. Brevo deployed a permanent fix on September 10, 2026 that strictly limits SSO access to the organization that owns the SSO configuration. The company simultaneously force-signed out all platform users and filed legal complaints with relevant authorities.","heading":"Technical Attack Vector: SAML SSO Boundary Failure","severity":"critical","sources":[{"credibility":1,"name":"Attacker gained access to client accounts — Brevo Status incident write-up","type":"official","url":"https://status.brevo.com/incidents/pawbvhq8/write-up"},{"credibility":2,"name":"Brevo SSO flaw enabled phishing through Trezor's newsletter — The Hack Academy","type":"news_article","url":"https://www.thehackacademy.com/news/brevo-sso-flaw-trezor-newsletter-phishing/"},{"credibility":2,"name":"Crypto customers targeted by scammers after email marketing provider breach — Malwarebytes","type":"news_article","url":"https://www.malwarebytes.com/blog/news/2026/09/crypto-customers-targeted-by-scammers-after-email-marketing-provider-breach"}]},{"content":"The phishing emails sent through Trezor's Brevo account carried the subject line 'Critical Security Alert: STM32 Entropy Vulnerability' and purported to originate from [email protected]. The message alleged a hardware flaw in the STM32 microcontrollers used in Trezor cold storage devices could expose seed phrases to brute-force attacks, and directed recipients to download an application that then asked for their wallet backup passphrase. Because the messages were transmitted through Brevo's own infrastructure under Trezor's authenticated sending account, they passed standard email authentication checks (SPF/DKIM/DMARC) that would typically flag spoofed sender addresses. Security researchers and Trezor itself confirmed there is no actual STM32 entropy defect and no legitimate notification campaign requesting seed phrase re-entry. The phishing domain was identified and disabled at the DNS level by Trezor within approximately 20 minutes of detection. Before takedown, approximately 2,500 users had clicked the malicious link. No confirmed cryptocurrency losses have been publicly attributed to the campaign as of September 17, 2026. Any user who entered a seed phrase or wallet backup into the distributed application should treat that wallet as fully compromised and immediately transfer funds to a newly generated wallet.","heading":"The Phishing Campaign: Fabricated STM32 Entropy Vulnerability","severity":"critical","sources":[{"credibility":1,"name":"Security incident at Brevo, our third-party email provider | Trezor","type":"official","url":"https://trezor.io/blog/news/security-incident-at-brevo-our-third-party-email-provider"},{"credibility":2,"name":"Trezor Hack Scare: That STM32 Entropy Email Is a Phishing Attack — CryptoTicker","type":"news_article","url":"https://cryptoticker.io/en/trezor-stm32-entropy-phishing-email/"},{"credibility":2,"name":"Trezor warns of Brevo phishing attack: 347,000 fake emails sent — Softonic","type":"news_article","url":"https://en.softonic.com/articles/trezor-warns-of-brevo-phishing-attack-347000-fake-emails-sent"},{"credibility":2,"name":"Trezor Says 347,000 Users Received Phishing Emails After Brevo Hack — SecurityWeek","type":"news_article","url":"https://www.securityweek.com/trezor-says-347000-users-received-phishing-emails-after-brevo-hack/"}]},{"content":"On September 14, 2026, attackers returned to Brevo's infrastructure via a separate vector. Using a long-lived Cloudflare API key that had been hardcoded in Brevo's application source code and carried full account permissions, the attacker deployed a malicious Cloudflare Worker. Between approximately 16:05 and 20:13 UTC on September 14, the worker modified content at the CDN edge for Brevo-controlled domains including brevo.com and sibforms.com, and injected malicious scripts into three JavaScript files that Brevo customers embed in their own websites. The injected scripts served selected visitors a fake 'Cloudflare: verify you are human' prompt using the ClickFix social engineering technique, which instructed victims to paste and run a command on their local machine. A second payload targeted WordPress site administrators, attempting to install a malicious WordPress plugin. Security researchers estimated over 100,000 customer-operated websites were affected during the window. All malicious subdomains stopped resolving on September 15, 2026, and Brevo's files were subsequently confirmed clean. This secondary attack is a distinct incident from the September 9 SSO breach, though both involved Brevo infrastructure.","heading":"Secondary Attack: Brevo Supply Chain Compromise (September 14, 2026)","severity":"critical","sources":[{"credibility":2,"name":"Brevo Supply Chain Attack Injects Malware Into 100,000 Websites — SecurityWeek","type":"news_article","url":"https://www.securityweek.com/brevo-supply-chain-attack-injects-malware-into-100000-websites/"},{"credibility":2,"name":"Brevo supply-chain attack injected ClickFix scripts on customer sites — BleepingComputer","type":"news_article","url":"https://www.bleepingcomputer.com/news/security/brevo-supply-chain-attack-injected-clickfix-scripts-on-customer-sites/"},{"credibility":2,"name":"Brevo supply chain attack hits 100k+ sites with WordPress backdoors and ClickFix malware — Sansec","type":"research","url":"https://sansec.io/research/brevo-supply-chain-attack"}]},{"content":"The Brevo phishing campaign was the second confirmed third-party supply-chain attack affecting Trezor customers within weeks. On August 10, 2026, Trezor was notified by ShipMonk, its shipping and logistics vendor, that customer data had been exposed via an SQL injection vulnerability (CVE-2026-72898, CVSS 10.0) in Metabase's password reset endpoint. Trezor initially disclosed on August 13, 2026 that approximately 13,689 customers who placed orders between May 10 and August 8, 2026 had names, email addresses, phone numbers, and shipping addresses exposed. Subsequently, Trezor disclosed that an additional 67,000 U.S. customers had records exposed — data covering orders from November 2019 through August 2021 that Trezor had previously stated was deleted. The ShipMonk breach totaled approximately 81,000 affected customers. The ShipMonk breach did not expose seed phrases, private keys, or wallet credentials, but the leaked personal data increased the plausibility of follow-on social engineering attacks, including the Brevo phishing campaign that used hardware-specific technical language to appear credible. The two incidents are separate, originate from different vendors, and involve different attack vectors.","heading":"Prior Incident: ShipMonk Breach (August 2026)","severity":"high","sources":[{"credibility":1,"name":"Recent customer data exposed in shipping provider incident | Trezor","type":"official","url":"https://trezor.io/blog/news/recent-customer-data-exposed-in-shipping-provider-incident"},{"credibility":2,"name":"Trezor Says ShipMonk Breach Exposed 67,000 U.S. Customers' Data It Said Was Deleted — The Hacker News","type":"news_article","url":"https://thehackernews.com/2026/09/trezor-says-shipmonk-breach-exposed.html"},{"credibility":2,"name":"Trezor data breach impact now reaches 81,000 customers — BleepingComputer","type":"news_article","url":"https://www.bleepingcomputer.com/news/security/trezor-data-breach-impact-now-reaches-81-000-customers/"},{"credibility":2,"name":"Trezor ShipMonk Breach Exposes 67,000 U.S. Customer Records via Metabase Zero-Day Vulnerability (CVE-2026-72898) — Rescana","type":"research","url":"https://www.rescana.com/post/trezor-shipmonk-breach-exposes-67-000-u-s-customer-records-via-metabase-zero-day-vulnerability-cve-2026-72898"}]},{"content":"The September 9 Brevo SSO breach was not limited to Trezor. BitBox (a hardware wallet manufacturer), CoinTracking (a crypto portfolio and tax reporting platform), and Solana Mobile (manufacturer of the Saga Web3 smartphone) all confirmed their Brevo accounts were among those accessed. BitBox and CoinTracking received similar impersonation-based phishing campaigns directed at their subscriber bases, though neither publicly reported confirmed fund losses attributable to those campaigns. Solana Mobile disclosed on September 12, 2026 via the Daily Hodl that it had suspended its marketing email account following confirmation of unauthorized access. Brevo's own post-incident disclosure states that 43 accounts had contact data exported and 6 accounts were used to send phishing emails — implying the six weaponized accounts spanned multiple vendors beyond Trezor alone.","heading":"Broader Impact: Other Affected Vendors","severity":"medium","sources":[{"credibility":2,"name":"Trezor, BitBox & CoinTracking Phishing Attack: Brevo Breach Explained — The CyberSec Guru","type":"news_article","url":"https://thecybersecguru.com/news/trezor-bitbox-cointracking-brevo-phishing-attack/"},{"credibility":2,"name":"Solana Mobile Suspends Marketing Email Account After Unauthorized Access — The Daily Hodl","type":"news_article","url":"https://dailyhodl.com/2026/09/13/solana-mobile-suspends-marketing-email-account-after-unauthorized-access/"},{"credibility":2,"name":"Solana Mobile warns users of phishing risks after Brevo breach — CryptoBriefing","type":"news_article","url":"https://cryptobriefing.com/solana-mobile-phishing-warning-brevo-breach/"}]},{"content":"Upon detecting the phishing campaign, Trezor took the following steps: disabled the malicious domain at the DNS level within approximately 20 minutes of detection; suspended its Brevo account to prevent further distribution; disabled its email-sending function; published a public warning across its website, Trezor Suite application, support channels, and community forums; and contacted all 347,149 affected newsletter subscribers. Trezor confirmed that Brevo does not store seed phrases, private keys, wallet credentials, or passwords — the exposure was limited to marketing contact data (email addresses and, where applicable, newsletter preferences). Trezor's official guidance states that no genuine Trezor communication will ever request a seed phrase or wallet backup, and that any message requesting such information should be treated as a phishing attempt regardless of the apparent sender. Trezor also noted that physical security of the hardware wallet device itself was not affected by this incident.","heading":"Trezor's Response and User Guidance","severity":"low","sources":[{"credibility":1,"name":"Security incident at Brevo, our third-party email provider | Trezor","type":"official","url":"https://trezor.io/blog/news/security-incident-at-brevo-our-third-party-email-provider"},{"credibility":2,"name":"Brevo breach exposes 347,000 Trezor users to phishing — BetaNews","type":"news_article","url":"https://betanews.com/article/brevo-breach-trezor-phishing/"}]},{"content":"The Brevo and ShipMonk incidents together illustrate a recurring attack surface for Trezor: the company's hardware wallet products have not been compromised, but three separate third-party service providers (Mailchimp in April 2022, ShipMonk in August 2026, and Brevo in September 2026) have each been breached in ways that exposed Trezor customer data or enabled targeted phishing. In the April 2022 Mailchimp incident, attackers similarly used access to a third-party email marketing account to send phishing emails to approximately 100 Trezor users after social engineering a Mailchimp employee. The concentration of high-value crypto user contact data across shared marketing and logistics SaaS platforms represents a systemic risk independent of any individual vendor. The Brevo incident specifically demonstrates that authenticated email infrastructure — where messages clear SPF/DKIM/DMARC checks — is an increasingly viable attack surface for seed-phrase extraction against hardware wallet customers.","heading":"Third-Party Vendor Risk Pattern","severity":"high","sources":[{"credibility":2,"name":"Trezor, BitBox users targeted in newsletter phishing spree — The Register","type":"news_article","url":"https://www.theregister.com/cyber-crime/2026/09/10/trezor-bitbox-users-targeted-in-newsletter-phishing-spree/5295496"},{"credibility":2,"name":"Explained: The Trezor/ShipMonk Breach (August 2026) — Halborn","type":"research","url":"https://www.halborn.com/blog/post/explained-the-trezor-shipmonk-breach-august-2026"},{"credibility":2,"name":"Hackers Hijack Trezor, Bitbox Emails to Target Crypto Users — Bitcoin.com News","type":"news_article","url":"https://news.bitcoin.com/security/hackers-hijack-trezor-bitbox-emails-to-target-crypto-users/"}]}],"sources_used":[{"credibility":1,"name":"Security incident at Brevo, our third-party email provider | Trezor","type":"official","url":"https://trezor.io/blog/news/security-incident-at-brevo-our-third-party-email-provider"},{"credibility":1,"name":"Attacker gained access to client accounts — Brevo Status incident write-up","type":"official","url":"https://status.brevo.com/incidents/pawbvhq8/write-up"},{"credibility":1,"name":"Scammers target hundreds of thousands of crypto owners after Trezor confirms data breach of email provider — TechCrunch","type":"news_article","url":"https://techcrunch.com/2026/09/11/scammers-target-hundreds-of-thousands-of-crypto-owners-after-trezor-confirms-data-breach-of-email-provider/"},{"credibility":2,"name":"Trezor: 347,000 users targeted in phishing attacks after Brevo breach — BleepingComputer","type":"news_article","url":"https://www.bleepingcomputer.com/news/security/trezor-347-000-users-targeted-in-phishing-attacks-after-brevo-breach/"},{"credibility":2,"name":"Trezor Says 347,000 Users Received Phishing Emails After Brevo Hack — SecurityWeek","type":"news_article","url":"https://www.securityweek.com/trezor-says-347000-users-received-phishing-emails-after-brevo-hack/"},{"credibility":2,"name":"Crypto customers targeted by scammers after email marketing provider breach — Malwarebytes","type":"news_article","url":"https://www.malwarebytes.com/blog/news/2026/09/crypto-customers-targeted-by-scammers-after-email-marketing-provider-breach"},{"credibility":2,"name":"Trezor, BitBox & CoinTracking Phishing Attack: Brevo Breach Explained — The CyberSec Guru","type":"news_article","url":"https://thecybersecguru.com/news/trezor-bitbox-cointracking-brevo-phishing-attack/"},{"credibility":2,"name":"Brevo Supply Chain Attack Injects Malware Into 100,000 Websites — SecurityWeek","type":"news_article","url":"https://www.securityweek.com/brevo-supply-chain-attack-injects-malware-into-100000-websites/"},{"credibility":2,"name":"Brevo supply-chain attack injected ClickFix scripts on customer sites — BleepingComputer","type":"news_article","url":"https://www.bleepingcomputer.com/news/security/brevo-supply-chain-attack-injected-clickfix-scripts-on-customer-sites/"},{"credibility":2,"name":"Brevo supply chain attack hits 100k+ sites with WordPress backdoors and ClickFix malware — Sansec","type":"research","url":"https://sansec.io/research/brevo-supply-chain-attack"},{"credibility":2,"name":"Solana Mobile Suspends Marketing Email Account After Unauthorized Access — The Daily Hodl","type":"news_article","url":"https://dailyhodl.com/2026/09/13/solana-mobile-suspends-marketing-email-account-after-unauthorized-access/"},{"credibility":2,"name":"Solana Mobile warns users of phishing risks after Brevo breach — CryptoBriefing","type":"news_article","url":"https://cryptobriefing.com/solana-mobile-phishing-warning-brevo-breach/"},{"credibility":1,"name":"Recent customer data exposed in shipping provider incident | Trezor","type":"official","url":"https://trezor.io/blog/news/recent-customer-data-exposed-in-shipping-provider-incident"},{"credibility":2,"name":"Trezor Says ShipMonk Breach Exposed 67,000 U.S. Customers' Data It Said Was Deleted — The Hacker News","type":"news_article","url":"https://thehackernews.com/2026/09/trezor-says-shipmonk-breach-exposed.html"},{"credibility":2,"name":"Trezor data breach impact now reaches 81,000 customers — BleepingComputer","type":"news_article","url":"https://www.bleepingcomputer.com/news/security/trezor-data-breach-impact-now-reaches-81-000-customers/"},{"credibility":2,"name":"Explained: The Trezor/ShipMonk Breach (August 2026) — Halborn","type":"research","url":"https://www.halborn.com/blog/post/explained-the-trezor-shipmonk-breach-august-2026"},{"credibility":2,"name":"Trezor ShipMonk Breach Exposes 67,000 U.S. Customer Records via Metabase Zero-Day (CVE-2026-72898) — Rescana","type":"research","url":"https://www.rescana.com/post/trezor-shipmonk-breach-exposes-67-000-u-s-customer-records-via-metabase-zero-day-vulnerability-cve-2026-72898"},{"credibility":2,"name":"Trezor, BitBox users targeted in newsletter phishing spree — The Register","type":"news_article","url":"https://www.theregister.com/cyber-crime/2026/09/10/trezor-bitbox-users-targeted-in-newsletter-phishing-spree/5295496"},{"credibility":2,"name":"Brevo breach exposes 347,000 Trezor users to phishing — BetaNews","type":"news_article","url":"https://betanews.com/article/brevo-breach-trezor-phishing/"},{"credibility":2,"name":"Hackers Hijack Trezor, Bitbox Emails to Target Crypto Users — Bitcoin.com News","type":"news_article","url":"https://news.bitcoin.com/security/hackers-hijack-trezor-bitbox-emails-to-target-crypto-users/"}],"summary":"On September 9, 2026, attackers exploited a SAML SSO misconfiguration at Brevo, Trezor's third-party email marketing provider, to access 138 Brevo customer accounts and send phishing emails to approximately 347,000 Trezor newsletter subscribers. The messages falsely claimed a critical STM32 microcontroller entropy vulnerability required users to re-enter their seed phrases; approximately 2,500 users clicked the malicious link before Trezor disabled the phishing domain within 20 minutes. No cryptocurrency losses have been confirmed as of mid-September 2026, but the incident forms part of a pattern of third-party supply-chain attacks targeting Trezor users across multiple vendor relationships.","timeline":[{"date":"2022-04-01","event":"Mailchimp, a prior Trezor email marketing provider, suffered a social engineering attack that exposed approximately 100 Trezor user accounts and enabled a targeted phishing campaign.","source":"The Register","source_url":"https://www.theregister.com/cyber-crime/2026/09/10/trezor-bitbox-users-targeted-in-newsletter-phishing-spree/5295496"},{"date":"2026-08-10","event":"ShipMonk, Trezor's shipping and logistics vendor, notified Trezor that customer data was exposed via a Metabase SQL injection zero-day (CVE-2026-72898, CVSS 10.0).","source":"Trezor official blog","source_url":"https://trezor.io/blog/news/recent-customer-data-exposed-in-shipping-provider-incident"},{"date":"2026-08-13","event":"Trezor publicly disclosed the ShipMonk breach, initially reporting approximately 13,689 affected customers with names, emails, phone numbers, and shipping addresses exposed.","source":"BleepingComputer","source_url":"https://www.bleepingcomputer.com/news/security/trezor-discloses-data-breach-affecting-nearly-14-000-customers/"},{"date":"2026-09-09","event":"Attackers exploited Brevo's SAML SSO misconfiguration, accessed 138 Brevo customer accounts, and sent phishing emails to approximately 347,149 Trezor newsletter subscribers. The emails used the subject line 'Critical Security Alert: STM32 Entropy Vulnerability' and directed recipients to a malicious application requesting seed phrase entry.","source":"Trezor official blog","source_url":"https://trezor.io/blog/news/security-incident-at-brevo-our-third-party-email-provider"},{"date":"2026-09-10","event":"Brevo detected the SSO access at 6:30 AM UTC and closed the attack vector by 8:30 AM UTC. Trezor disabled the phishing domain within approximately 20 minutes of detection, by which time approximately 2,500 users had clicked the malicious link. Brevo force-signed out all platform users and deployed a permanent SSO scope-restriction fix.","source":"Brevo Status incident write-up","source_url":"https://status.brevo.com/incidents/pawbvhq8/write-up"},{"date":"2026-09-11","event":"TechCrunch reported that Trezor confirmed the Brevo data breach and described it as the second data breach of a Trezor third-party vendor within weeks.","source":"TechCrunch","source_url":"https://techcrunch.com/2026/09/11/scammers-target-hundreds-of-thousands-of-crypto-owners-after-trezor-confirms-data-breach-of-email-provider/"},{"date":"2026-09-12","event":"Solana Mobile disclosed that its Brevo marketing email account had been accessed without authorization as part of the same Brevo incident and warned users of elevated phishing risk.","source":"CryptoBriefing","source_url":"https://cryptobriefing.com/solana-mobile-phishing-warning-brevo-breach/"},{"date":"2026-09-13","event":"Solana Mobile confirmed it had suspended its Brevo marketing email account following unauthorized access.","source":"The Daily Hodl","source_url":"https://dailyhodl.com/2026/09/13/solana-mobile-suspends-marketing-email-account-after-unauthorized-access/"},{"date":"2026-09-14","event":"In a separate secondary attack, attackers used a hardcoded Cloudflare API key to deploy a malicious Cloudflare Worker on Brevo's domains and customer-embedded JavaScript files between approximately 16:05 and 20:13 UTC, injecting ClickFix malware and WordPress backdoor payloads across an estimated 100,000+ customer websites.","source":"SecurityWeek","source_url":"https://www.securityweek.com/brevo-supply-chain-attack-injects-malware-into-100000-websites/"},{"date":"2026-09-15","event":"All malicious subdomains from the September 14 Cloudflare Worker attack stopped resolving. Brevo's JavaScript files were confirmed clean.","source":"BleepingComputer","source_url":"https://www.bleepingcomputer.com/news/security/brevo-supply-chain-attack-injected-clickfix-scripts-on-customer-sites/"},{"date":"2026-09-17","event":"Trezor updated its disclosure to confirm 347,149 total marketing contacts were affected by the Brevo breach. No confirmed cryptocurrency losses from the phishing campaign were reported as of this date.","source":"Trezor official blog","source_url":"https://trezor.io/blog/news/security-incident-at-brevo-our-third-party-email-provider"}]},"v":1}Verify offline (run on your own machine)python -m src.verify_decision 5896f141-1dd8-4d3d-9aec-f25e0102714b
How verification works. The “Row integrity” check above is computed in your browser — your machine recomputes the SHA-256 of the canonical bytes and compares against the stored hash. No avoid.net server can fake that check. The “full verify” link goes one level deeper: your browser fetches the on-chain transaction from a Solana RPC node and confirms the same hash is in the memo. If you don’t want to trust either avoid.net or the public RPC, run the CLI verifier on your own machine —
python -m src.verify_decision <event_id>.