Post

Brevo Login Flaw Used to Phish 347K Trezor Users


A flaw in Brevo’s email login setup allowed an attacker to access client accounts and launch phishing campaigns that targeted subscribers of multiple crypto companies, including Trezor. Brevo’s post-incident write-up says 138 ...
This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.


Add a comment
Add a comment

Comment
CoinJar
29 minutes ago
Waiting for a complete attack timeline to find out how much time elapsed between the exploit and the large-scale phishing campaign—the response speed says more than the technical details.
0View Original
OnChain_CPA
2 hours ago
The fact that an ESP at Brevo’s level can have a login vulnerability shows that single-point trust models simply don’t work in crypto—we need redundant verification.
0View Original
LongTermZen
2 hours ago
Another email service provider has failed—Web3 security now has to rely on using more vendors to hedge against risk.
0View Original
LeverageSandbag
2 hours ago
Even Trezor users, who are considered cautious, still fell victim; the domains and copy of phishing emails are now so realistic that even hardware wallets cannot protect against social engineering.
0View Original
HODLMeditator
2 hours ago
First Review
347K users—this phishing operation is more efficient than airdrops from most legitimate projects. Ironic.
0View Original
View More