Brevo Breach Exposes 347,000 Trezor Users to Phishing

A Brevo breach exposed 138 customer accounts and enabled phishing emails to reach about 347,000 Trezor newsletter subscribers. The campaign used the subject line “Critical Security Alert: STM32 Entropy Vulnerability” and directed users to a fake application requesting wallet backups or recovery phrases. Trezor disabled the malicious domain within 20 minutes, but about 2,500 people had already visited the link. Brevo said the attackers exploited a failure in access boundaries linked to its single sign-on configuration. Six accounts sent phishing emails, while contact data from 43 accounts was exported. BitBox and CoinTracking also reported similar unauthorised activity through Brevo, although neither found evidence that corporate credentials, customer funds or recovery phrases were stolen. The Brevo breach highlights persistent crypto phishing and supply-chain risks. Traders should verify security alerts through official channels and never submit wallet backups or seed phrases. The incident is unlikely to cause a direct cryptocurrency price impact, but could temporarily weaken confidence in wallet providers and crypto security platforms.
Neutral
The Brevo breach does not indicate that any cryptocurrency network, token or customer wallet was directly compromised. Trezor disabled the malicious domain quickly, and BitBox and CoinTracking reported no evidence of stolen funds or recovery phrases. As a result, the event is unlikely to create sustained selling pressure in major cryptocurrencies. In the short term, affected users may reduce activity or move assets while checking their accounts, which could cause limited and temporary disruption. The main risk is reputational: repeated phishing incidents may weaken confidence in wallet providers and increase demand for stricter security controls. Unless further evidence shows that private keys, seed phrases or funds were stolen, the longer-term price impact should remain neutral.