Solana Mobile Warns Users Of Phishing Risks Following Brevo Security Breach
- Solana Mobile disclosed unauthorized access to its third-party marketing provider, Brevo, prompting immediate account suspension and a security warning for its user base.
- The breach exposed 138 customer accounts across the crypto sector, including Trezor, enabling large-scale phishing campaigns targeting hundreds of thousands of users.
- Attackers exploited a SAML Single Sign-On vulnerability to access legitimate email infrastructure, using it to distribute fraudulent security alerts and steal wallet backups.
- Solana Mobile emphasized that no emails were sent from its compromised account, but warned users to remain vigilant against credential-harvesting attempts.
Solana Mobile confirmed a security incident involving its third-party email marketing provider, Brevo. The company identified unauthorized access to its Brevo account, which affected some customer accounts, and immediately disabled the account to mitigate risk. SolanaSOL-- Mobile is currently collaborating with Brevo to determine the full scope of the information accessed.
To date, the company states that no emails were sent from the Solana Mobile account during the incident, though verification is ongoing. In its announcement, Solana Mobile emphasized standard security protocols, reminding users that the company will never ask for seed phrases, private keys, or wallet recovery details. This incident highlights the broader security risks associated with third-party service providers in the cryptocurrency sector.
The breach is part of a larger supply-chain attack on email provider Brevo that allowed hackers to exploit SSO flaws to send convincing phishing emails to crypto companies like Trezor, CoinTracking, and BitBox. An authorization flaw in Brevo’s login system allowed an attacker to access 138 customer accounts, leading to phishing emails sent through accounts used by Trezor, BitBox, and CoinTracking. Brevo traced the incident to a weakness in how its platform handled permissions for users belonging to multiple organizations.
The attacker created a Brevo account, enabled single sign-on (SSO), and invited legitimate users. Instead of being limited to the attacker's organization, the SSO configuration incorrectly granted access to all organizations those users could reach. Six accounts were used to send phishing emails, and contacts were exported from 43 accounts. This incident follows a separate data breach affecting Trezor’s third-party shipping provider, ShipMonk, which exposed personal information of nearly 14,000 people and an additional 67,000 US customers, potentially increasing the risk of targeted phishing attacks.
What Was The Scope Of The Brevo Breach?
A vulnerability in Brevo's SAML single-sign-on system allowed attackers to compromise 138 customer accounts, including Solana Mobile's marketing platform. This breach exposed hundreds of thousands of crypto users to targeted phishing campaigns by weaponizing exported contact lists rather than directly stealing wallet keys. Email marketing platforms serve as critical infrastructure for crypto companies, but a recent breach at Brevo (formerly Sendinblue) highlights significant structural risks in third-party vendor management.
On September 9-10, 2026, attackers exploited a flaw in Brevo’s SAML SSO handling, gaining unauthorized access to 138 customer accounts. SAML, or Security Assertion Markup Language, facilitates single-sign-on authentication; when misconfigured, it can allow attackers to forge or hijack authentication tokens without passwords. The impact was concentrated in the crypto sector. Attackers weaponized six accounts to send phishing emails and exported contact lists from 43 accounts.
Trezor disclosed that phishing emails reached approximately 347,000 of its newsletter subscribers. Other firms like BitBox and CoinTracking also confirmed their Brevo accounts were compromised. Solana Mobile warned users of elevated phishing risks, noting that while its own account was not among the 138 compromised, the broader exposure warranted a public alert.
How Did The Phishing Campaign Operate?
Trezor reported that roughly 347,000 customers received phishing emails after a third-party marketing platform, Brevo, was hacked. Brevo explained that an attacker exploited how the platform handles SAML Single Sign-On (SSO). The attacker enabled SSO on their account and invited legitimate users, using their identity provider to sign in. The access was not properly scoped; instead of being limited to the single organization where SSO was enabled, it wrongly granted the attacker access to all organizations those users could reach.
The attacker sent phishing messages to email addresses stored under six of the 138 compromised accounts and exfiltrated contacts from 43 accounts. One of the targeted customers was Trezor, which warned customers that the phishing emails contained a subject line reading “Critical Security Alert: STM32 Entropy Vulnerability” and a link to a malicious website. Trezor warned that funds could be lost if users entered their wallet backup into the site. Approximately 2,500 users clicked the link before it was taken offline 20 minutes after detection.

The phishing campaigns followed a standard playbook: impersonating trusted brands, creating urgency around fabricated security issues, and directing users to malicious credential-harvesting pages. Crucially, the attackers did not compromise private keys or wallets directly; instead, they leveraged legitimate contact data to increase the credibility of their attacks. This incident underscores a due diligence gap for crypto businesses. Companies can secure their own internal systems, but remain vulnerable to upstream vendor misconfigurations. The breach demonstrates that contact lists built over years of marketing can become attack infrastructure if third-party platforms are not rigorously vetted for security posture and incident response capabilities.
Why Is This Relevant To Investors Now?
An authorization boundary failure in Brevo's SAML SSO system allowed an attacker to access 138 customer accounts, including Trezor, enabling a phishing campaign targeting 347,000 users with wallet backup theft lures. Access to legitimate email infrastructure allowed fraudulent messages to be distributed in a way that passed normal email authentication checks. Trezor’s phishing email, titled “Critical Security Alert: STM32 Entropy Vulnerability,” directed recipients to a malicious application requesting wallet backups. Anyone providing their recovery phrase can recreate the wallet and control its funds.
Trezor’s Brevo account contained roughly 347,000 opt-in newsletter email addresses. The initial phishing message was sent to all addresses, and Trezor took the malicious domain offline within 20 minutes. Approximately 2,500 people accessed the link before the takedown. Trezor is treating all 347,000 newsletter addresses as potentially known to the attacker and reusable for future phishing attempts. The company confirmed that its hardware wallets, wallet backups, and internal systems were not compromised, and customers who did not enter their backup phrases remained safe.
Additionally, the attacker exported contacts from 43 accounts, potentially leaving address lists available for use outside Brevo’s mailing infrastructure. This incident follows other phishing attempts against Trezor, including fake sponsored search results and physical mail scams in 2026. Trezor also recently disclosed a separate data exposure involving logistics provider ShipMonk, which affected nearly 81,000 customers' personal information. The broader implications for the Solana ecosystem and crypto infrastructure providers highlight the critical need for rigorous third-party risk management in the digital asset space.
Blending traditional trading wisdom with cutting-edge cryptocurrency insights.
Latest Articles
Stay ahead of the market.
Get curated U.S. market news, insights and key dates delivered to your inbox.



Comments
No comments yet