email icons
Image: Le Vu via Unsplash

Multiple crypto companies warn customers of phishing emails after alleged provider breach

Editor's Note: Story updated 3:20 p.m. Eastern time with postmortem from Brevo.

Thousands of cryptocurrency holders were inundated with phishing emails on Wednesday after hackers breached an email provider and sent out corrupted messages. 

Popular cryptocurrency companies Trezor, CoinTracking and BitBox confirmed that phishing emails were sent out to customers subscribed to their newsletters.

Trezor and BitBox did not confirm which email provider was breached but CoinTracking said email service provider Brevo was the source of the phishing emails. 

BitBox noted that multiple other crypto companies targeted “all share the same newsletter provider.” 

Brevo released its own notice on Thursday morning warning that an attacker had access to 120 customer accounts. 

“The bad actor used the access to send phishing emails to the client's contactbase. The access has been closed,” the company said.

Brevo declined to answer a series of questions, instead sending Recorded Future News a postmortem published on Thursday afternoon. The company said 138 Brevo accounts were breached and six of those were used to send phishing emails to the contacts stored there.

The attackers exported contacts from 43 accounts. The company claims it has removed the hacker from the system. 

Brevo provided a detailed technical explanation for how the hackers broke in, essentially describing an attack in which the intruders stole the login information of legitimate users and expanded their access through a vulnerability in the system.  

The company said it has deployed a permanent fix for the exploited issue and plans to cooperate with authorities. 

Brevo was founded in Paris as an email marketing firm in 2012, and raised more than $580 million in December to help expand to other parts of its customer relationship management business.

Security alert phishing

Each of the emails sent out used the legitimate company domains and purported to be focused on security issues requiring customer action. 

People who received the emails said they were alarmed at how legitimate they looked, and several clicked on the links before being taken to phishing websites that were nearly identical to the legitimate platforms. 

For Trezor customers, people received an email titled “Critical Security Alert: STM32 Entropy Vulnerability” that urged them to click a link and take specific actions to address alleged security issues. 

Trezor, a hardware wallet manufacturer, released a message on social media saying their third-party email provider was breached and that the email did not come from them. 

“Do not click on any link. We have taken down the domain, and we are investigating the situation, including how the hackers got access to our legit domain,” the company said. 

Trezor, which recently suffered a different breach exposing the personal details of 81,000 customers, also posted a notice on its website about the fake email. 

CoinTracking said hackers sent an email titled “Data Breach Notice: Please refresh API Keys as soon as possible” to its customers that contained a malicious link. 

BitBox explained that it sent a phishing warning to all its newsletter subscribers, contacted the provider and reported the phishing domains. 

“Most of the phishing links appear to have been taken down already. We are still actively investigating this situation and will update you once we know more,” BitBox said. 

Multiple data breaches involving cryptocurrency companies like Trezor and others have raised concerns about the exposure of identifying information related to digital currency owners. During the takedown of a noted cryptocurrency theft ring, DOJ prosecutors noted that the criminals ranked targets using lists of cryptocurrency owners stolen from cryptocurrency companies. 

After Trezor’s recent data breach involving its shipping and logistics provider, customers of the company reported getting malicious QR codes by postal mail. 

Experts have also seen an increase in wrench attacks — where wealthy cryptocurrency owners have been targeted and attacked in real life.

The number of wrench attacks grew 33 percent year-over-year, according to blockchain security audit company CertiK. The losses have reached $124 million so far this year, compared with $10.5 million reported in the first half of 2025. 

Two weeks ago, cryptocurrency investor Harry Chun Tak Yeh was found dead after falling from his luxury 30th floor apartment in Paraguay. Police found his door open and said his home ​​had been ransacked.

Recorded Future
No previous article
No new articles
Jonathan Greig

Jonathan Greig

is a Breaking News Reporter at Recorded Future News. Jonathan has worked across the globe as a journalist since 2014. Before moving back to New York City, he worked for news outlets in South Africa, Jordan and Cambodia. He previously covered cybersecurity at ZDNet and TechRepublic.