Multiple crypto companies warn customers of phishing emails after alleged provider breach
Attackers compromised 120 Brevo email accounts and sent convincing phishing emails to Trezor, BitBox, and CoinTracking newsletter subscribers.
Trezor, BitBox, and CoinTracking confirmed that phishing emails were sent to newsletter subscribers after a compromise of their shared email provider, which CoinTracking identified as Brevo. Brevo said an attacker accessed 120 customer accounts and used them to send phishing emails from legitimate company domains, including fake security alerts like 'Critical Security Alert: STM32 Entropy Vulnerability' and 'Data Breach Notice: Please refresh API Keys.' Trezor had already suffered a separate breach exposing details of 81,000 customers, and CertiK reports physical wrench attacks on crypto holders rose 33 percent year-over-year with $124 million in losses in 2026.
- Brevo confirmed attacker access to 120 customer accounts used to send phishing emails.
- Phishing emails came from legitimate company domains urging API-key and security actions.
- Trezor took down the phishing domain and warned customers not to click links.
- CertiK: wrench attacks up 33 percent year-over-year with $124 million lost in 2026.
Full article642 words · extracted from therecord.media · click to collapse
Thousands of cryptocurrency holders were inundated with phishing emails on Wednesday after hackers breached an email provider and sent out corrupted messages. Popular cryptocurrency companies Trezor, CoinTracking and BitBox confirmed that phishing emails were sent out to customers subscribed to their newsletters. Trezor and BitBox did not confirm which email provider was breached, but CoinTracking said email service provider Brevo was the source of the phishing emails. BitBox noted that multiple other crypto companies targeted “all share the same newsletter provider.” Brevo did not respond to requests for comment but released its own notice on Thursday morning warning that an attacker had access to 120 customer accounts. “The bad actor used the access to send phishing emails to the client's contactbase. The access has been closed,” the company said, pledging to post a full post mortem at a later date. Brevo was founded in Paris as an email marketing firm in 2012, and raised more than $580 million in December to help expand to other parts of the customer relationship management business. Each of the emails sent out used the legitimate company domains and purported to be focused on security issues requiring customer action. People who received the emails said they were alarmed at how legitimate they looked, and several clicked on the links before being taken to phishing websites that were nearly identical to the legitimate platforms. For Trezor customers, people received an email titled “Critical Security Alert: STM32 Entropy Vulnerability” that urged them to click a link and take specific actions to address alleged security issues. Trezor, a hardware wallet manufacturer, released a message on social media saying their third-party email provider was breached and that the email did not come from them. “Do not click on any link. We have taken down the domain, and we are investigating the situation, including how the hackers got access to our legit domain,” the company said. Trezor, which recently suffered a different breach exposing the personal details of 81,000 customers, also posted a notice on its website about the fake email. CoinTracking said hackers sent an email titled “Data Breach Notice: Please refresh API Keys as soon as possible” to its customers that contained a malicious link. BitBox explained that it sent a phishing warning to all its newsletter subscribers, contacted the provider and reported the phishing domains. “Most of the phishing links appear to have been taken down already. We are still actively investigating this situation and will update you once we know more,” BitBox said. Multiple data breaches involving cryptocurrency companies like Trezor and others have raised concerns about the exposure of identifying information related to digital currency owners. During the takedown of a noted cryptocurrency theft ring, DOJ prosecutors noted that the criminals ranked targets using lists of cryptocurrency owners stolen from cryptocurrency companies. After Trezor’s recent data breach involving its shipping and logistics provider, customers of the company reported getting malicious QR codes by postal mail. Experts have also seen an increase in wrench attacks — where wealthy cryptocurrency owners have been targeted and attacked in real life. The number of wrench attacks grew 33 percent year-over-year, according to blockchain security audit company CertiK. The losses have reached $124 million so far this year, compared with $10.5 million reported in the first half of 2025. Two weeks ago, cryptocurrency investor Harry Chun Tak Yeh was found dead after falling from his luxury 30th floor apartment in Paraguay. Police found his door open and said his home had been ransacked. Security alert phishing
No previous article
No new articles
Jonathan Greig
is a Breaking News Reporter at Recorded Future News. Jonathan has worked across the globe as a journalist since 2014. Before moving back to New York City, he worked for news outlets in South Africa, Jordan and Cambodia. He previously covered cybersecurity at ZDNet and TechRepublic.
Text extracted automatically; images, tables and formatting may be missing. Original: https://therecord.media/trezor-bitbox-cointracking-phishing-crypto-holders