Verify a decision
Every moderation decision on AVOID.NET is anchored to the Solana blockchain. You don't have to trust us — you can verify cryptographically that we committed to a verdict at a specific moment and have not rewritten it.
How verification works
- We commit. When a moderator accepts/rejects a submission, we serialize the decision into deterministic UTF-8 bytes (
payload_canonical_string), hash it with SHA-256, encode the digest as base58, and write it to Solana inside an SPL Memo v2 transaction. - We store the bytes. The exact bytes we hashed are stored alongside the decision in our database. Anyone can read them and recompute the hash in any language.
- You compare three values. Database hash, your independently-recomputed hash, and the hash inside the on-chain memo. If all three match, the decision is authentic and timestamped.
The on-chain memo format is
AVOID.NET|v1|h:<b58-sha256>|d:<id>|t:<iso>Find a signature on any investigation page's decision log, or run python -m src.verify_decision --signature <sig> for a CLI check.
Decision
- Sequence
- #1
- Score
- →
- Cluster
- mainnet-beta
- Slot
- 446488248
- Off-chain at
- 2026-09-12T17:38:23.310Z
- Anchored at
- —
- Block time
- —
Independent verification
- 1. Database (off-chain)
- Ghr9cGpBafETecr4FoHEs96frKLUJwH5SJ7zh393f3C8
- 2. Recomputed (your browser)
- computing…
- 3. On-chain (Solana memo)
- fetching…
Canonical bytes hashed (18056 chars)
{"actor":"system:backfill","investigation_id":"b7cc3a07-409e-446f-9a79-ba333505a2f3","kind":"publish","page_slug":"brevo-email-marketing-platform-used-by-trezor-bitbox-cointracking-solana-mobile","published_at":"2026-09-12T17:38:23.157Z","sequence_num":1,"snapshot":{"content_type":"investigation","entity_name":"Brevo (email marketing platform used by Trezor, BitBox, CoinTracking, Solana Mobile)","sections":[{"content":"According to Brevo's own incident write-up and multiple news outlets, an attacker exploited a flaw in how Brevo implements SAML single sign-on (SSO). The attacker created a Brevo account, enabled SSO on it, and invited legitimate Brevo customer accounts into that SSO configuration. Using their own identity provider, the attacker was then able to authenticate as those invited users. Brevo has stated that the access this granted was \"not properly scoped\": rather than being confined to the single organization where SSO was enabled, it wrongly granted the attacker access to every organization those invited users could reach, according to reporting by SecurityWeek and Cointelegraph. Brevo initially reported 120 affected customer accounts and later revised this to 138 accounts in its postmortem, per The Record (Recorded Future News) and multiple outlets citing Brevo's own statements.","heading":"Nature of the Incident: SAML SSO Authorization Flaw","severity":"critical","sources":[{"credibility":2,"name":"Trezor Says 347,000 Users Received Phishing Emails After Brevo Hack - SecurityWeek","type":"news_article","url":"https://www.securityweek.com/trezor-says-347000-users-received-phishing-emails-after-brevo-hack/"},{"credibility":2,"name":"Brevo Login Breach Affected Trezor, BitBox and CoinTracking - Cointelegraph","type":"news_article","url":"https://cointelegraph.com/news/brevo-login-flaw-trezor-bitbox-cointracking-phishing"},{"credibility":1,"name":"Multiple crypto companies warn customers of phishing emails after alleged provider breach - The Record","type":"news_article","url":"https://therecord.media/trezor-bitbox-cointracking-phishing-crypto-holders"},{"credibility":1,"name":"Attacker gained access to client accounts - Brevo Status page","type":"official","url":"https://status.brevo.com/incidents/01M266V1CZKJQNGZRNEGFD5CQE"}]},{"content":"Of the 138 Brevo customer accounts to which the attacker gained unauthorized access, Brevo has stated that 6 accounts were actually used to send phishing emails to the contacts stored in them, and 43 accounts had their contact/mailing lists exported by the attacker without a phishing email necessarily following. Brevo has said the remaining accounts (roughly 93) showed no meaningful malicious activity. This means the exposure was not limited to companies that received a phishing email; an unknown number of additional Brevo customers may have had subscriber email addresses exfiltrated for potential future use, a point corroborated across SecurityWeek, Cointelegraph, and Malwarebytes reporting.","heading":"Scope of the Breach","severity":"high","sources":[{"credibility":2,"name":"Trezor Says 347,000 Users Received Phishing Emails After Brevo Hack - SecurityWeek","type":"news_article","url":"https://www.securityweek.com/trezor-says-347000-users-received-phishing-emails-after-brevo-hack/"},{"credibility":2,"name":"Crypto customers targeted by scammers after email marketing provider breach - Malwarebytes","type":"research","url":"https://www.malwarebytes.com/blog/news/2026/09/crypto-customers-targeted-by-scammers-after-email-marketing-provider-breach"}]},{"content":"Trezor confirmed in its own official blog post that Brevo, the third-party marketing platform it uses for newsletter campaigns, suffered the security incident, and that the attacker sent a phishing email to roughly 347,000 addresses stored in Trezor's Brevo account. The phishing email carried the subject line \"Critical Security Alert: STM32 Entropy Vulnerability\" (also reported by some outlets, quoting Trezor communications, as \"Critical Security Alert: STM32 Entropy Bug Identified\") and directed recipients to a malicious site that prompted them to download an app requesting entry of their wallet backup (seed phrase). Trezor states it detected the campaign and had the malicious domain taken down at the DNS level within about 20 minutes, but that roughly 2,500 people had already clicked the link by that point. Trezor has said that \"Brevo's system holds no passwords, wallet data, or other personal information,\" that no Trezor product, wallet, or account system was affected, and that customers who did not enter their wallet backup anywhere other than their physical Trezor device remain secure. The company is treating all ~347,000 addresses as known to the attacker and reusable in future phishing attempts.","heading":"Impact on Trezor","severity":"critical","sources":[{"credibility":1,"name":"Security incident at Brevo, our third-party email provider - Trezor official blog","type":"official","url":"https://trezor.io/blog/news/security-incident-at-brevo-our-third-party-email-provider"},{"credibility":2,"name":"Trezor Says 347,000 Users Received Phishing Emails After Brevo Hack - SecurityWeek","type":"news_article","url":"https://www.securityweek.com/trezor-says-347000-users-received-phishing-emails-after-brevo-hack/"},{"credibility":2,"name":"Brevo Login Breach Affected Trezor, BitBox and CoinTracking - Cointelegraph","type":"news_article","url":"https://cointelegraph.com/news/brevo-login-flaw-trezor-bitbox-cointracking-phishing"}]},{"content":"Hardware wallet maker BitBox confirmed via a public statement, reported by Cointelegraph and The Record, that its Brevo account was compromised and used to send an unauthorized phishing email that appeared to have reached its full newsletter and tutorial subscriber list. BitBox said its Brevo account stored only email addresses and language preferences, and that it found no evidence at the time of compromised company credentials, downloaded contacts, lost customer funds, or disclosed recovery phrases, while cautioning it was still awaiting full logs from Brevo. BitBox stated: \"Most of the phishing links appear to have been taken down already. We are still actively investigating this situation.\" Crypto portfolio-tracking and tax platform CoinTracking also had its Brevo account used to distribute a phishing email with the subject line \"Data Breach Notice: Please refresh API Keys as soon as possible,\" attempting to lure recipients into entering account credentials or API keys, per Cointelegraph and Malwarebytes reporting.","heading":"Impact on BitBox and CoinTracking","severity":"critical","sources":[{"credibility":2,"name":"Brevo Login Breach Affected Trezor, BitBox and CoinTracking - Cointelegraph","type":"news_article","url":"https://cointelegraph.com/news/brevo-login-flaw-trezor-bitbox-cointracking-phishing"},{"credibility":1,"name":"Multiple crypto companies warn customers of phishing emails after alleged provider breach - The Record","type":"news_article","url":"https://therecord.media/trezor-bitbox-cointracking-phishing-crypto-holders"},{"credibility":2,"name":"Crypto customers targeted by scammers after email marketing provider breach - Malwarebytes","type":"research","url":"https://www.malwarebytes.com/blog/news/2026/09/crypto-customers-targeted-by-scammers-after-email-marketing-provider-breach"}]},{"content":"Solana Mobile issued a public warning to its users about elevated phishing risk in the wake of the Brevo incident, as reported by Crypto Briefing. Available reporting indicates Solana Mobile's own Brevo account was not confirmed among the 138 accounts to which the attacker gained access; its advisory appears to have been precautionary, aimed at users who might receive fraudulent emails impersonating the Solana Mobile brand given the broader exposure of the Brevo customer base. This is a notable distinction from Trezor, BitBox, and CoinTracking, whose accounts were directly used to send phishing emails or had data exported. This claim about Solana Mobile's status should be treated as provisional pending a direct statement from Solana Mobile or Brevo explicitly listing which named companies were among the compromised accounts versus which issued only precautionary warnings.","heading":"Solana Mobile's Warning — Status Not Fully Confirmed as Compromised","severity":"medium","sources":[{"credibility":2,"name":"Solana Mobile warns users of phishing risks after Brevo breach - Crypto Briefing","type":"news_article","url":"https://cryptobriefing.com/solana-mobile-phishing-warning-brevo-breach/"}]},{"content":"Brevo publicly acknowledged the incident via its official status page and its official X/Twitter account. Brevo stated: \"This morning we have closed a security incident that allowed an attacker to access 120 Brevo accounts. The majority of those have no suspicious activity. The bad actor used the access to send phishing emails to the client's contactbase. The access has been closed as of 11:30AM CEST,\" a figure the company later revised upward to 138 accounts in its published postmortem. Brevo's status page marked the incident \"Resolved\" with a timestamped update reading \"Thu, Sep 10, 2026, 08:30 AM,\" stating that \"the issue has been resolved, and all affected services are now functioning normally.\" Per reporting by The Record, Brevo said it has deployed a permanent fix for the exploited authorization issue and plans to cooperate with law enforcement authorities investigating the intrusion.","heading":"Brevo's Response and Remediation","severity":"medium","sources":[{"credibility":1,"name":"Attacker gained access to client accounts - Brevo Status page","type":"official","url":"https://status.brevo.com/incidents/01M266V1CZKJQNGZRNEGFD5CQE"},{"credibility":1,"name":"Brevo official statement on X (@brevo_official)","type":"official","url":"https://x.com/brevo_official/status/2098013044227915777"},{"credibility":1,"name":"Multiple crypto companies warn customers of phishing emails after alleged provider breach - The Record","type":"news_article","url":"https://therecord.media/trezor-bitbox-cointracking-phishing-crypto-holders"}]},{"content":"This incident illustrates a supply-chain risk pattern relevant to any crypto company or user: a vulnerability in a third-party marketing/CRM vendor allowed an attacker to send phishing emails from the real, authenticated sending domains and infrastructure of trusted crypto brands, making the messages far more convincing than typical spoofed phishing (they passed from the legitimate Brevo-managed sending records of Trezor, BitBox, and CoinTracking). Recipients of unexpected \"critical security alert,\" \"data breach notice,\" or similar urgent emails from any crypto company that uses Brevo for newsletters should independently verify such messages through the company's official app or website before clicking links or entering any wallet seed phrase, private key, password, or API key, none of which legitimate companies request via email. Because 43 accounts reportedly had contact lists exported without a phishing email necessarily following immediately, secondary or delayed phishing campaigns using this stolen data remain a plausible ongoing risk beyond the initial September 2026 wave.","heading":"Supply-Chain Risk for Crypto Users of Brevo-Based Services","severity":"high","sources":[{"credibility":1,"name":"Security incident at Brevo, our third-party email provider - Trezor official blog","type":"official","url":"https://trezor.io/blog/news/security-incident-at-brevo-our-third-party-email-provider"},{"credibility":2,"name":"Crypto customers targeted by scammers after email marketing provider breach - Malwarebytes","type":"research","url":"https://www.malwarebytes.com/blog/news/2026/09/crypto-customers-targeted-by-scammers-after-email-marketing-provider-breach"}]}],"sources_used":[{"credibility":1,"name":"Security incident at Brevo, our third-party email provider - Trezor official blog","type":"official","url":"https://trezor.io/blog/news/security-incident-at-brevo-our-third-party-email-provider"},{"credibility":1,"name":"Attacker gained access to client accounts - Brevo Status page","type":"official","url":"https://status.brevo.com/incidents/01M266V1CZKJQNGZRNEGFD5CQE"},{"credibility":1,"name":"Brevo official statement on X (@brevo_official)","type":"official","url":"https://x.com/brevo_official/status/2098013044227915777"},{"credibility":1,"name":"Scammers target hundreds of thousands of crypto owners after Trezor confirms data breach of email provider - TechCrunch","type":"news_article","url":"https://techcrunch.com/2026/09/11/scammers-target-hundreds-of-thousands-of-crypto-owners-after-trezor-confirms-data-breach-of-email-provider/"},{"credibility":1,"name":"Multiple crypto companies warn customers of phishing emails after alleged provider breach - The Record","type":"news_article","url":"https://therecord.media/trezor-bitbox-cointracking-phishing-crypto-holders"},{"credibility":2,"name":"Trezor Says 347,000 Users Received Phishing Emails After Brevo Hack - SecurityWeek","type":"news_article","url":"https://www.securityweek.com/trezor-says-347000-users-received-phishing-emails-after-brevo-hack/"},{"credibility":2,"name":"Trezor: 347,000 users targeted in phishing attacks after Brevo breach - BleepingComputer","type":"news_article","url":"https://www.bleepingcomputer.com/news/security/trezor-347-000-users-targeted-in-phishing-attacks-after-brevo-breach/"},{"credibility":2,"name":"Brevo Login Breach Affected Trezor, BitBox and CoinTracking - Cointelegraph","type":"news_article","url":"https://cointelegraph.com/news/brevo-login-flaw-trezor-bitbox-cointracking-phishing"},{"credibility":2,"name":"Trezor phishing attack traced to Brevo login authorization flaw - crypto.news","type":"news_article","url":"https://crypto.news/trezor-phishing-attack-traced-to-brevo-login-authorization-flaw/"},{"credibility":2,"name":"Solana Mobile warns users of phishing risks after Brevo breach - Crypto Briefing","type":"news_article","url":"https://cryptobriefing.com/solana-mobile-phishing-warning-brevo-breach/"},{"credibility":2,"name":"Crypto customers targeted by scammers after email marketing provider breach - Malwarebytes","type":"research","url":"https://www.malwarebytes.com/blog/news/2026/09/crypto-customers-targeted-by-scammers-after-email-marketing-provider-breach"}],"summary":"Brevo, a Paris-based email marketing and CRM platform (formerly Sendinblue) used by numerous crypto companies for newsletters, suffered a SAML single sign-on (SSO) authorization flaw that an attacker exploited around September 9-10, 2026 to access 138 customer accounts. Six of those accounts, including ones belonging to hardware wallet maker Trezor, hardware wallet maker BitBox, and portfolio tracker CoinTracking, were used to send convincing phishing emails to hundreds of thousands of real subscribers from the companies' legitimate domains, prompting some recipients to enter sensitive wallet information. Brevo says it closed the access path and issued a fix within hours, but the incident is a documented supply-chain risk for any crypto business or user relying on Brevo-delivered newsletters.","timeline":[{"date":"2026-09-09","date_evidence":"On September 9, 2026, Brevo, the third-party marketing platform Trezor uses for newsletter campaigns, suffered a security incident affecting 120 Brevo accounts.","event":"Trezor states, in its own official blog post, that Brevo suffered the security incident affecting 120 Brevo accounts (later revised by Brevo to 138).","source":"Trezor official blog","source_url":"https://trezor.io/blog/news/security-incident-at-brevo-our-third-party-email-provider"},{"date":"2026-09","event":"An attacker creates a Brevo account, enables SAML SSO on it, and invites legitimate Brevo customer accounts into that configuration, exploiting an authorization-scoping flaw to gain access to 138 customer accounts without needing their passwords.","source":"SecurityWeek / Cointelegraph reporting on Brevo's postmortem","source_url":"https://www.securityweek.com/trezor-says-347000-users-received-phishing-emails-after-brevo-hack/"},{"date":"2026-09","event":"Phishing emails are sent from 6 compromised Brevo accounts, including Trezor's, BitBox's, and CoinTracking's, to their real subscriber lists; Trezor's email (subject referencing an 'STM32 Entropy' vulnerability) reaches roughly 347,000 addresses. The malicious site is taken down at the DNS level roughly 20 minutes after detection, by which point about 2,500 recipients had clicked the link.","source":"Trezor official blog / Cointelegraph","source_url":"https://cointelegraph.com/news/brevo-login-flaw-trezor-bitbox-cointracking-phishing"},{"date":"2026-09-10","date_evidence":"Thu, Sep 10, 2026, 08:30 AM","event":"Brevo marks the incident \"Resolved\" on its public status page, stating the issue has been resolved and all affected services are functioning normally.","source":"Brevo Status page","source_url":"https://status.brevo.com/incidents/01M266V1CZKJQNGZRNEGFD5CQE"},{"date":"2026-09","date_original":"2026-09-10","event":"Brevo posts a public statement on X confirming an attacker accessed 120 (later revised to 138) customer accounts and used the access to send phishing emails; Brevo states the unauthorized access was closed as of 11:30 AM CEST.","source":"Brevo official X account","source_url":"https://x.com/brevo_official/status/2098013044227915777"},{"date":"2026-09","date_original":"2026-09-11","event":"Trezor, BitBox, and CoinTracking publicly warn customers of the phishing emails; mainstream outlets including TechCrunch, SecurityWeek, BleepingComputer, and Cointelegraph report on the breach and its impact on crypto users. Solana Mobile also issues a precautionary phishing warning to its users.","source":"TechCrunch","source_url":"https://techcrunch.com/2026/09/11/scammers-target-hundreds-of-thousands-of-crypto-owners-after-trezor-confirms-data-breach-of-email-provider/"}]},"v":1}