Brevo said an attacker accessed 138 accounts through a login flaw, with phishing emails sent from accounts belonging to Trezor, BitBox and CoinTracking.

Hardware wallet maker Trezor said a fake security alert claimed a hardware flaw could expose users’ recovery phrases.

Phishing emails sent to Trezor and BitBox users falsely warned of critical security flaws and attempted to lure recipients into clicking malicious links.

Attackers exploit legitimate mailing channels to demand crypto wallet backups