
An attacker exploited a flaw in email platform Brave’s login system to access 138 client accounts, enabled a phishing email to reach roughly 347,000 Trezor newsletter subscribers, and distributed fraudulent messages through accounts at hardware wallet maker Bitbox and crypto-tracking platform Crypto-Tracking Platform.
A postmortem on Thursday, bravo said Six accounts were used to send phishing emails, contacts were exported from 43, and 93 accounts showed no meaningful activity. The platform did not specify whether the categories overlapped.
The attacker created a Bravo account, enabled single sign-on, and invited legitimate Bravo users to the configuration. Bravo said access should have been limited to that organization, but an authorization boundary failed and access was granted to every organization that could reach the invited users.
The disclosure expands on warnings issued by Treasure and Bitbox on Wednesday, identifying their shared provider and explaining why the emails passed simple authentication checks and appeared to be genuine.
Cointelegraph reached out to Bravo for more information but did not receive a response prior to publication.
Crypto firms assess potential customer exposure
And a blog post, Trezor said The phishing message titled “Critical Security Alert: STM32 Entropy Vulnerability” contained a link to an app that requested users to back up their wallets. The company disabled the domain at the DNS level within 20 minutes, but about 2,500 people accessed the link before the takedown.
A Treasury spokesperson told Cointelegraph that “the initial email was sent to 347,000 customers,” all of whom were subsequently contacted about the risk. The company’s Bravo account stores only opt-in newsletter email addresses and no other customer data.
“Until we hear more from Bravo, we are treating approximately 347,000 newsletter addresses that are known to the attacker and potentially reusable for phishing,” the spokesperson said.
Related: Liquid Network resumes block production after absorbing $320M
A Bitbox spokesperson told Cointelegraph that its unauthorized email was sent through Bravo and appears to have reached the entire newsletter and tutorial list.
Beatbox says Bravo only has email address and language preferences. It found no evidence of compromised company credentials, downloaded contacts, lost funds or disclosed recovery phrases, but is considering the list as possible access while waiting for Bravo’s logs.
Meanwhile, CoinTracking said Its Bravo account distributed an email titled “Data Breach Notification: Refresh API Key ASAP.” It warned recipients not to follow links in the email.
magazine: 10 Biggest Unsolved Crypto Mysteries
