On 9 September 2026, roughly 347,000 people subscribed to hardware wallet maker Trezor's newsletter received an email with the subject line Critical Security Alert: STM32 Entropy Vulnerability. It claimed a hardware flaw in the chip used in Trezor devices, and linked to an app that asked for the recipient's wallet backup.

Subscribers of BitBox, another wallet maker, and of the crypto tax and portfolio platform CoinTracking received their own versions. CoinTracking's told customers to refresh their API keys.

None of the messages were spoofed. They were sent from the companies' own accounts at Brevo, the Paris-founded email marketing platform, which is why they passed the checks mail systems use to catch forged senders.

Brevo has since published a post-mortem, and the way in is worth understanding precisely, because it is not the one first reported.

What Brevo says happened

Brevo says it identified the problem at 06:30 UTC on 10 September. An attacker had exploited a flaw in how Brevo handles SAML single sign-on to reach 138 customer accounts. Six were used to send phishing to the contacts stored in them. Contacts were exported from 43. The remaining 93 showed no meaningful activity. At 08:30 UTC Brevo closed the route and signed out every user on the platform.

The method, in Brevo's telling, took three moves.

  1. The attacker opened an ordinary Brevo account and switched on single sign-on for it.
  2. The attacker invited genuine Brevo users into that single sign-on configuration.
  3. Using an identity provider the attacker controlled, the attacker signed in as those invited users.

Brevo points out that the third step, on its own, is how single sign-on is meant to behave. The failure was scope. A login that arrived through the attacker's configuration should have reached only the attacker's organisation. Instead, it reached every organisation those users belonged to.

Early coverage described attackers stealing the login details of legitimate users. Brevo's own account involves no stolen password at all.

Why an invitation was enough

Single sign-on works by delegation. A company tells a service such as Brevo which identity provider speaks for its staff, and when that provider says a given person has logged in, the service believes it. The trust is supposed to be bounded: a provider vouches for people in its own organisation, and for nothing else.

By inviting real users into a configuration they controlled, the attacker made their own identity provider an authority for those users. Brevo then treated that provider's word as good for the users' access everywhere on the platform, including the organisations where those users sent real companies' newsletters.

Brevo's account describes no use of the victims' own passwords or second factors. What the attacker needed was to know whom to invite. Brevo's fix matches the diagnosis: single sign-on access limited strictly to the organisation that owns the configuration, with single sign-on invitations switched back on once that is in place.

The counts, and what they add up to

Brevo's first public notice, on the morning of 10 September, put the number of affected accounts at 120, the figure Trezor also used. The post-mortem, published later that day, said 138.

The breakdown has an overlap worth noticing. Take away the 93 accounts with no meaningful activity and 45 remain. But 6 accounts sent phishing and 43 had contacts exported, which makes 49. So at least four accounts were used for both: mailed from, and emptied.

Why the emails looked real

The standard sender checks, SPF, DKIM and DMARC, answer in different ways a single question: did this message really come from the domain it claims? Here the answer was genuinely yes. Brevo says the messages went through legitimate infrastructure and passed the usual authentication checks.

The same routing gave Trezor its fastest lever. Trezor says Brevo routes all of its communication through Trezor's own domain, which let it take the phishing link down at the DNS level within 20 minutes of spotting it. By then, about 2,500 people had clicked. Trezor says clicking alone does not put funds at risk; entering a wallet backup does.

It is Trezor's second third-party breach in a matter of weeks. Its fulfilment provider ShipMonk exposed tens of thousands of customers' home addresses, disclosed earlier this month. Trezor now says it is treating all of the roughly 347,000 newsletter addresses as known to the attacker and possibly reusable for phishing.

What to do

  • If you entered a wallet backup anywhere after one of these emails, move your funds to a new wallet immediately, as Trezor advises.
  • Treat any message asking for a recovery phrase as phishing, whatever its sender checks say. Trezor says it will never ask for one.
  • If your company sends email through a marketing platform, ask the provider whether single sign-on sessions are confined to the organisation that configured them, who can invite users into your organisation, and whether contact exports are logged and alerted on.
  • Check which outside identity providers your SaaS accounts trust, and remove any you do not recognise.

What is not established

  • How the attacker chose whom to invite, and whether an invitation had to be accepted before it could be used.
  • When access began. Trezor dates the phishing to 9 September; Brevo identified the flaw at 06:30 UTC the next day.
  • Which companies were among the 138, and which of the 43 had their contacts exported. Trezor says it cannot yet confirm whether its list was.
  • How long the scoping flaw existed before it was exploited.
  • How many recipients entered a wallet backup.