The information provided in this article is for informational purposes only and does not constitute financial advice. Cryptocurrency investments carry a high degree of risk. Always conduct your own research.

Waltio Confirms Brevo Breach Touched Its User Emails: Here Is What To Do Now

Waltio has told users its Brevo account was accessed during the September breach that also hit Trezor and BitBox. Here is what was exposed.

crypto news
6 min read
Share:

French crypto tax platform Waltio has started emailing its users about a security incident at Brevo, the third party email provider it uses to send campaigns. The message is calm, carefully worded, and mostly reassuring. It is also the latest confirmation that the Brevo breach of early September has a longer guest list than anyone first thought.

If you are a Waltio user, your tax reports are fine. Your email address may not be. And in crypto, an email address in the wrong hands is not a small thing.

What Did Waltio Actually Tell Its Users?

The notice, sent in French under the heading "Information relative à la sécurité de vos données personnelles", sets out four points.

  • First, no malicious emails went out from Waltio's account. Nothing was blasted to the contact list pretending to be Waltio.
  • Second, Brevo's analysis is still running. Brevo has not been able to confirm whether the intruder actually viewed or exported Waltio's contact list, only that unauthorised access to the account happened.
  • Third, the data at risk is thin. The only fields Waltio keeps inside Brevo are the email address tied to your Waltio account and, if you entered it voluntarily, your French department number. That is the two digit administrative region code used in France, so 75 for Paris, 13 for Bouches du Rhône, and so on. Useful for regional tax messaging, and not much else on its own.
  • Fourth, the blast radius stops at Brevo. Waltio says the tool holds no passwords, no API keys, no wallet addresses, no transaction history and no tax data. Logins and connected exchanges are untouched. Waltio also notes that Brevo now treats the incident as closed.

How Big Was The Brevo Breach?

Bigger than one French startup. Brevo said an attacker got into around 120 to 138 customer accounts on 9 and 10 September before access was cut off. The company later attributed it to an authorisation flaw in its login and single sign on layer rather than a classic password leak, which meant the attacker could reach every organisation the compromised invited users were entitled to see.

Brevo's own breakdown split the damage three ways: a handful of accounts were used to send phishing, several dozen had contact lists exported, and the large majority showed no activity at all. Waltio's "analysis in progress" language suggests it is sitting somewhere between the second and third bucket, and does not yet know which.

The names already confirmed are a who's who of crypto: Trezor, BitBox, CoinTracking and Solana Mobile. Trezor got the worst of it. Roughly 347,000 newsletter subscribers received a fake security alert about an STM32 entropy vulnerability, pointing to an app that asked for their wallet backup. Trezor killed the domain at DNS level within twenty minutes, but around 2,500 people had already clicked.

Screenshot 2026-09-15 175052.png

Why Does This Matter More For Waltio Than For Other Brevo Clients?

Because Waltio has been here before, and much worse.

In January 2026 the platform suffered a genuine intrusion into its own systems, not a vendor's. Attackers exfiltrated data tied to tax report generation, contacted the company demanding a ransom, and the Paris prosecutor's cybercrime unit handed the investigation to the Gendarmerie's national cyber unit. Waltio confirmed that email addresses, aggregated crypto balances and tax report data had been exposed, while passwords, API keys, wallet addresses and banking details had not. A file circulating on Telegram afterwards was reportedly used to target French crypto holders directly.

That history changes the maths on this new incident. A standalone email address is low value. An email address that can be cross referenced against a leaked file showing roughly how much crypto you hold is a targeting list. France has had a grim run of kidnappings and home invasions aimed at crypto holders, and those cases start with exactly this kind of data stitching.

So the correct reading of the Waltio notice is not "nothing happened". It is "one more identifier of yours may now be in circulation, and you should assume the attackers are patient".

How Do You Spot A Waltio Phishing Email?

The Brevo attack worked precisely because the phishing came through legitimate infrastructure. Sender domain checks, DKIM, SPF, the usual tells, all of it looked correct on the Trezor emails. So domain inspection alone will not save you here.

Judge the ask instead:

  • Any message asking for your seed phrase or wallet backup is fraud. Always. Waltio states plainly that it will never ask for a seed phrase, a password or a transfer of funds, by email or by phone.
  • Any message pushing you to download an application to "fix" or "verify" something is fraud.
  • Any message creating a deadline, a legal threat or a tax penalty scare is worth a second look. Tax angles are the obvious hook for a Waltio user list.
  • Never click through from the email. Type waltio.com yourself, or contact support directly at hello@waltio.com.
Advertisement
CT-Shop

What Should Waltio Users Do Right Now?

Nothing dramatic, but a few things are worth doing this week.

Turn on two factor authentication on your Waltio account and on every exchange it connects to, using an authenticator app rather than SMS. Review and revoke any exchange API keys you no longer use, and confirm the ones you keep are read only. Change your Waltio password if you have reused it anywhere else. Consider running your address through a breach checker to see what else about you is already public.

And the boring one that actually matters: reduce how much you talk about your holdings, on social media and off it. Data leaks like this one are only the first step. The value is in combining them.

One structural note is hard to avoid. Crypto tax tools sit on the richest dataset in the entire ecosystem, a complete picture of who owns what and where it sits. DAC8 reporting obligations across the EU are pushing more of that data into more places, not fewer. The Waltio notice is a reminder that the weakest link is rarely the platform itself. It is the newsletter tool bolted onto the side of it.

Keeping your keys off the internet entirely is still the strongest answer to any phishing campaign. The CryptoTicker shop stocks hardware wallets at shop.cryptoticker.io.

Related articles

More from CryptoTicker