Don't want to trade it yourself?
Our desk runs DEX portfolios on profit share.
Nadia Dubois
September 14, 2026
14 min read
Solana Mobile told users on September 12, 2026, that its marketing email account had been accessed without authorization as part of a wider security incident at Brevo, the third-party email platform the company uses for newsletters. The disclosure, first reported by CoinEdition, lands just days after hardware wallet maker Trezor confirmed roughly 347,000 of its newsletter subscribers were caught up in the same breach. Together, the two disclosures point to a single root cause: a SAML single sign-on flaw at Brevo that let an outside attacker reach into customer accounts across the platform, including at least two prominent names in the crypto industry.
The Solana Mobile Brevo breach is not, by itself, a compromise of the Solana blockchain, Seeker hardware, or any user’s wallet. But it is a reminder that the weakest link in crypto security is often not a smart contract or a private key — it is the ordinary marketing software that every company, crypto or not, uses to send newsletters. Here is what happened, what Solana Mobile and Brevo have said, and what it means for anyone who has ever handed an email address to a crypto company.
Don’t miss new tech stories on Google
Add Tech Insider once in the Google app and our stories appear in your news suggestions.
Solana Mobile Confirms Brevo Breach Exposed Its Marketing Account
Solana Mobile, the company behind the Saga and Seeker Android handsets built for the Solana ecosystem, posted on X on September 12 that its third-party marketing email provider, Brevo, had experienced a security incident affecting a number of customer accounts, including its own. The company said it had identified unauthorized access to its Brevo account, disabled the account outright, and was working with Brevo to determine exactly what information an attacker may have reached.
Crucially, Solana Mobile said it had no evidence that any unauthorized emails had actually been sent from its account, though the company said it was still verifying that with Brevo. Even without confirmed outbound phishing traffic tied to the Solana Mobile account specifically, the company urged its subscribers to treat any email claiming to be from Solana Mobile with suspicion, particularly anything asking for a seed phrase, private key, or wallet recovery information. Solana Mobile has repeatedly stressed it will never request that information by email.
What Happened: Inside the Brevo SAML SSO Vulnerability
Brevo, formerly known as Sendinblue, is an email marketing and CRM platform used by thousands of businesses to run newsletters, transactional emails, and marketing automation. According to Brevo’s own incident write-up and reporting from outlets including <a href="https://techcrunch.com/2026/09/11/scammers-target-hundreds-of-thousands-of-crypto-owners-after-trezor-confirms-data-breach-of-email-provider/” rel=”nofollow noopener” target=”_blank”>TechCrunch, an attacker exploited a flaw in how Brevo’s SAML single sign-on system handled organization invitations. Attacker-created SSO invitations wrongly granted cross-organization access, meaning that in a properly functioning system the flaw should never have let one customer’s session reach into another customer’s account.
That misconfiguration is what turned a single exploit into a platform-wide incident. Instead of compromising one company’s Brevo account through stolen credentials or a phishing email aimed at an employee, the attacker appears to have used the SSO boundary flaw itself to hop between accounts, giving them a foothold across a large number of unrelated Brevo customers in one campaign, a technique similar to the SSO weaknesses exploited in the recent Dropbox breach via Lenovo ID SSO. Brevo has said it identified and fixed the SSO boundary issue as part of its incident response.
The Numbers: 138 Accounts, Six Active Phishing Runs, 43 Exported Lists
Brevo’s own account of the incident, cited by multiple outlets covering the Solana Mobile Brevo breach, put the scale at 138 customer accounts accessed through the SAML SSO vulnerability. Of those, Brevo said six accounts were used to actively send phishing emails to their own stored contact lists, 43 accounts had their contact lists exported without any phishing emails necessarily being sent from them, and the remaining 93 accounts showed no meaningful attacker activity beyond the initial access. Trezor, in its own blog post published the same week, described the incident at roughly 120 affected Brevo accounts when it first went public, a figure that was refined upward as Brevo’s investigation continued.
| Category | Accounts | What It Means |
|---|---|---|
| Total Brevo accounts accessed | 138 | Reached via the SAML SSO vulnerability |
| Accounts used to send phishing emails | 6 | Attacker sent messages directly to stored contacts |
| Accounts with contact lists exported | 43 | Email addresses taken, no phishing send confirmed from those accounts |
| Accounts with no meaningful activity | 93 | Accessed but not visibly abused |
| Trezor newsletter addresses considered exposed | ~347,000 | Treated as compromised out of caution |
Solana Mobile has not published its own account-level breakdown of how many subscriber emails were in its Brevo account or whether its list falls into the exported, phished, or untouched bucket. The company’s statement said only that it is still working with Brevo to determine the scope of information accessed on its account specifically.
Timeline of the Breach and Disclosure
September 9-10: The Intrusion
The technical breach window at Brevo is reported as September 9-10, 2026, the period during which the attacker exploited the SAML SSO flaw to move across customer accounts. Trezor published its own blog post on September 9, disclosing that its Brevo-hosted newsletter database had been compromised and that phishing emails using a spoofed Trezor identity had already gone out to subscribers.
September 11-13: The Disclosure Cascade
TechCrunch’s report on September 11 framed the incident as scammers targeting hundreds of thousands of crypto owners following Trezor’s confirmation. Solana Mobile followed on September 12 with its own statement on X, acknowledging unauthorized access to its Brevo account and confirming it had disabled the account. Coverage from CoinEdition, CryptoBriefing, and regional crypto outlets followed through September 13, each adding detail on Brevo’s account-level breakdown as the company’s investigation progressed.
Solana Mobile’s Official Statement, In Its Own Words
In its post on X, Solana Mobile framed the incident squarely as a vendor problem rather than an internal failure: its third-party marketing email provider, Brevo, experienced a security incident affecting some customer accounts, including Solana Mobile’s. The company said it identified the unauthorized access to its Brevo account, disabled the account, and is working with Brevo to understand the scope of information accessed. Solana Mobile added that, to its knowledge, no emails have been sent from the Solana Mobile account as a result of the breach, while noting that verification with Brevo is ongoing.
That statement matters for two reasons. First, it puts Solana Mobile in the same posture Trezor was in before its own investigation matured: an early, cautious disclosure that does not yet rule out follow-on phishing waves. Second, it reinforces a standing security message that Solana Mobile and virtually every hardware wallet or crypto device maker now repeats after every vendor incident — legitimate companies do not ask for seed phrases, private keys, or wallet recovery details over email, full stop.
Why Trezor’s 347,000 Exposed Addresses Matter for Solana Mobile Users
Trezor’s disclosure is the most concrete data point available in the entire Solana Mobile Brevo breach story, and it is worth understanding in detail because it shows what the worst-case outcome looks like. Trezor said its opt-in newsletter database, containing approximately 347,000 email addresses, was affected by the Brevo incident. Because Trezor could not immediately confirm whether its contact list had actually been exported by the attacker, the company chose to treat all 347,000 addresses as potentially known to the attacker going forward, rather than wait for full certainty.
That is the scenario Solana Mobile subscribers should keep in mind. Even if Solana Mobile eventually confirms that no phishing emails were sent directly from its own Brevo account, an exported contact list from the broader Brevo incident could still surface in future campaigns that impersonate Solana Mobile, Solana ecosystem apps, or unrelated brands entirely, a pattern already seen in other recent crypto wallet-adjacent breaches. Trezor’s own guidance to its users was blunt: the exposed addresses could be reused for other phishing attacks down the line, not just the initial wave.
What Data Was — and Wasn’t
Every company touched by the Brevo incident, including Trezor and Solana Mobile, has been consistent on one point: Brevo does not store passwords, seed phrases, private keys, or wallet data. The platform is a marketing tool, not an authentication or custody system, so the categories of data at risk are limited to what a newsletter provider actually holds.
- Email addresses of newsletter subscribers and marketing contacts
- Contact list metadata associated with those addresses inside Brevo’s standard fields
- No passwords, seed phrases, private keys, or on-chain wallet data, according to statements from Brevo, Trezor, and Solana Mobile
That distinction is real, but it should not be read as reassurance that the breach is low-stakes. An email address alone is enough to run a convincing, targeted phishing campaign against a known crypto user base, especially when the messages are sent through infrastructure that email providers trust.
Why These Phishing Emails Are Especially Hard to Spot
The detail that separates the Brevo incident from a garden-variety phishing wave is delivery. Because the attacker sent messages through Brevo’s own legitimate sending infrastructure using compromised customer accounts, those emails passed standard authentication checks like SPF, DKIM, and DMARC. In plain terms, the messages looked genuine to email clients and spam filters because, technically, they came from real, authorized senders on Brevo’s platform — the accounts themselves were simply hijacked. Brevo’s response included disabling links inside identified phishing emails, but that mitigation only covers messages already flagged, not new campaigns built from exported contact lists.
For everyday users, the practical lesson is that “the email looks legitimate” is no longer a reliable signal on its own. A message can pass every automated authenticity check and still be malicious if the account that sent it, or the list it was sent to, came from a breach like this one. As an illustrative example of what to watch for, the domain in the sender address and the domain in any link should match the company’s real domain exactly, not a close variant:
Legitimate: solanamobile.com
Suspicious: solana-mobile-secure.com
Suspicious: solanamobile-support.net
Suspicious: account.solanamobile.io-verify.com
None of those suspicious examples are domains confirmed to be used in this specific campaign — they are illustrations of the lookalike-domain pattern that phishing kits typically rely on once they have a verified list of real subscriber addresses to target.
Historical Context: Marketing Platforms Keep Becoming Crypto’s Weak Link
This is not the first time an email marketing vendor has become the entry point for a crypto-focused phishing campaign, and Trezor has the unfortunate distinction of appearing in more than one of them. In April 2022, Mailchimp disclosed that an attacker had used social engineering against its own employees to access an internal support tool, viewing 319 customer accounts and exporting audience data from 102 of them, with the incident specifically concentrated on customers in cryptocurrency and finance. Trezor was among the companies hit, and its Mailchimp-hosted newsletter list was used to send phishing emails urging recipients to download a fake Trezor Suite application designed to capture wallet recovery seeds.
A few months later, in August 2022, Twilio disclosed a breach tied to the “0ktapus” SMS phishing campaign, in which attackers impersonating Twilio’s IT department tricked employees into entering credentials on spoofed login pages. Twilio said data for 125 of its customers, including Signal, was accessed, and 93 Authy two-factor accounts were compromised. The broader 0ktapus campaign was found to have stolen close to 9,931 credentials from more than 130 organizations using 169 phishing domains, with Mailchimp again turning up among the affected companies in that wider sweep.
| Incident | Date | Root Cause | Scale | Crypto Impact |
|---|---|---|---|---|
| Mailchimp breach | April 2022 | Social engineering of employees, internal tool access | 319 accounts viewed, 102 exported | Trezor newsletter used for wallet-seed phishing |
| Twilio / 0ktapus | August 2022 | SMS phishing of employees, spoofed SSO pages | 125 Twilio customers, 93 Authy accounts, 130+ orgs campaign-wide | Mailchimp and other crypto-serving vendors also hit |
| Brevo breach | September 2026 | SAML SSO cross-organization access flaw | 138 accounts accessed | Trezor (~347,000 addresses), Solana Mobile |
The pattern across all three incidents is consistent: attackers do not need to breach a crypto company’s own servers if they can instead breach the marketing vendor that already holds a verified, opt-in list of that company’s most engaged users. Each incident used a different technical route in, from social engineering to SMS phishing to an SSO configuration flaw, but the payoff was the same — a ready-made target list of people already primed to trust emails from a specific crypto brand.
Market and Industry Impact
The direct market impact of the Solana Mobile Brevo breach is limited in scope compared with a protocol-level exploit or an exchange hack like the $320 million Liquid Network drain, and reporting so far has not tied any measurable price movement in SOL to this specific incident. The more meaningful impact is reputational and operational. Solana Mobile, which has spent the past two years trying to establish its Seeker handset as a trusted, security-forward device for the Solana ecosystem, now has to spend cycles reassuring subscribers that a vendor-side breach did not touch device security or on-chain assets.
For Brevo, the incident adds to a growing list of email marketing platforms — alongside Mailchimp and, indirectly, Twilio — that have been singled out as supply-chain weak points for the crypto industry specifically. That reputational cost tends to show up gradually, in the form of crypto and fintech customers migrating to providers with SSO configurations they can audit more directly, or moving sensitive newsletter operations in-house rather than relying on a shared third-party platform.
Competitive Comparison: How the Response Stacks Up
Judged purely on incident response, Brevo’s handling compares reasonably well with the Mailchimp and Twilio precedents. Brevo published account-level numbers (138 accessed, six actively phished, 43 exported, 93 untouched) faster than Mailchimp did in 2022, and it disabled links inside identified phishing emails as an active mitigation step. Trezor’s decision to treat its entire 347,000-address list as compromised, rather than wait for Brevo to confirm exactly which portion was exported, mirrors the same cautious posture Twilio eventually adopted with its Authy user base in 2022.
Where Solana Mobile’s response differs is in its earlier framing: the company disabled its Brevo account immediately upon discovering unauthorized access and issued a public statement within roughly 48 hours of TechCrunch’s initial report on the broader Brevo incident, rather than waiting for a confirmed phishing wave tied specifically to its own account before saying anything. That faster public disclosure, even without a confirmed phishing send, is closer to the standard privacy and security researchers have pushed vendors toward since the Mailchimp and Twilio episodes: disclose on evidence of unauthorized access, not on confirmed harm.
What Solana Mobile and Crypto Users Should Do Right Now
The practical guidance from Solana Mobile, Trezor, and Brevo converges on a short list of steps that apply to anyone who has ever subscribed to a crypto company’s newsletter, not just Solana Mobile and Trezor customers specifically.
- Treat any email requesting a seed phrase, private key, or wallet recovery phrase as fraudulent — Solana Mobile and Trezor both state they will never ask for this information by email
- Avoid clicking links in unsolicited “security alert” or “urgent verification” emails, even if the sender address looks correct
- Navigate directly to a company’s official site or app instead of following an email link, and verify any claimed incident through the company’s official blog or verified social accounts
- Assume your email address may be known to attackers if you have ever subscribed to a Solana Mobile or Trezor newsletter, and stay alert to phishing attempts for the foreseeable future, not just this week
- Enable two-factor authentication on any exchange or wallet-adjacent account where it is available, and avoid reusing passwords across services
None of these steps require a technical background. They are the same habits that limited the damage from the Mailchimp and Twilio incidents in 2022, and they remain the most effective defense against a breach that fundamentally targets human trust rather than cryptographic keys. Readers who want a step-by-step hardening guide can also see our walkthrough on setting up phishing-resistant MFA to block credential-based attacks like this one before they succeed.
Regulatory and Legal Outlook
As of this writing, there is no public confirmation of a formal regulatory enforcement action tied specifically to the Brevo incident. Given the scale involved, hundreds of thousands of email addresses spanning crypto users in multiple jurisdictions, the breach likely falls within the scope of general data-protection frameworks such as the EU’s GDPR, which typically require breach notification to relevant authorities and affected individuals within a defined window once a company becomes aware of unauthorized access to personal data.
Coverage of the incident so far has focused on technical mitigation and user warnings rather than legal proceedings, which mirrors the early stage of the Mailchimp and Twilio incidents before lawsuits and regulatory scrutiny followed in the months after initial disclosure. Whether the Brevo breach follows the same trajectory will depend largely on how many downstream phishing victims come forward and whether any of them can trace financial losses directly back to the exposed contact lists.
What Happens Next: Five Predictions
- More Brevo customers beyond Trezor and Solana Mobile will likely come forward in the coming weeks as they complete their own reviews of the 138 affected accounts.
- Expect additional phishing waves built from the exported contact lists over the following months, not just an immediate spike, mirroring how the Mailchimp-Trezor exposure kept generating phishing attempts long after the original 2022 disclosure.
- Crypto-focused companies will increasingly move newsletter operations to platforms offering stricter SSO auditing, or bring list management in-house, following the same pattern seen after the Mailchimp and Twilio incidents.
- Brevo will face pressure to publish a full post-incident technical report detailing the SSO fix, similar to the transparency Twilio eventually provided around its Authy compromise.
- Watch for at least one class-action inquiry or regulatory information request tied to the scale of the breach, given the precedent set by other large-scale marketing-platform incidents affecting financial and crypto customers.
Frequently Asked Questions
Was Solana blockchain or Solana Mobile’s Seeker hardware compromised?
No. The Solana Mobile Brevo breach affected a third-party marketing email account, not the Solana blockchain, Solana Mobile’s device firmware, or any on-chain wallet infrastructure. Solana Mobile has said its Brevo account was disabled after unauthorized access was discovered.
How many Solana Mobile accounts were affected by the Brevo breach?
Solana Mobile has not published an exact figure for how many of its subscriber emails were exposed. The company has said it is still working with Brevo to determine the scope of information accessed on its account.
What is Brevo and why do crypto companies use it?
Brevo, formerly Sendinblue, is a third-party email marketing and CRM platform used by companies across many industries, including crypto, to send newsletters and marketing communications. Solana Mobile and Trezor both used Brevo for their subscriber newsletters at the time of the breach.
Did the attacker get access to wallet seed phrases or private keys?
No. Brevo, Trezor, and Solana Mobile have each stated that Brevo does not store passwords, seed phrases, private keys, or wallet data. The exposure is limited to marketing contact data such as email addresses.
How is this different from the 2022 Mailchimp breach that also hit Trezor?
The 2022 Mailchimp breach relied on social engineering of Mailchimp employees to access an internal tool, exposing 319 viewed accounts and 102 with exported data. The 2026 Brevo breach instead exploited a flaw in how Brevo’s SAML SSO system handled organization invitations, giving the attacker cross-account access that reached 138 accounts. Both incidents targeted crypto and finance customers specifically and both hit Trezor.
Should I stop using Solana Mobile’s Seeker phone because of this breach?
There is no indication that the breach affects Seeker hardware, its software, or its wallet functionality. The incident is limited to a marketing email vendor. The main risk to users is phishing emails, not a compromise of the device itself.
What should I do if I already clicked a link in a suspicious email claiming to be from Solana Mobile or Trezor?
If you entered a seed phrase, private key, or wallet recovery information on a page reached through a suspicious link, treat that wallet as compromised and move funds to a new wallet with a freshly generated seed phrase as soon as possible. If you only clicked a link but did not enter sensitive information, monitor your accounts and avoid entering any credentials on the page you were sent to.
Has Brevo said how the SSO vulnerability was fixed?
Brevo has acknowledged the SAML SSO boundary flaw that allowed cross-organization access and has said it addressed the underlying issue as part of its incident response, though a full technical post-mortem had not been published as of this report.
Related Coverage
Source: tech-insider.org
![Solana Mobile Brevo Breach: 138 Accounts Hacked [2026] Solana Mobile Brevo Breach: 138 Accounts Hacked [2026]](https://xpertsstudio.com/wp-content/uploads/2026/09/solana-mobile-brevo-breach-2026-1-1024x585.webp)