Waltio Confirms Brevo Breach Touched Its User Emails: Here Is What To Do Now
Waltio has told users its Brevo account was accessed during the September breach that also hit Trezor and BitBox. Here is what was exposed.




Which topics should we dive deeper into?
Select what genuinely interests you. Your picks feed directly into our editorial planning.
Crypto news that's actually worth your time.
Weekly. 60 seconds. Carefully curated by our editors: no hype, no promo flood, no spam.
French crypto tax platform Waltio has started emailing its users about a security incident at Brevo, the third party email provider it uses to send campaigns. The message is calm, carefully worded, and mostly reassuring. It is also the latest confirmation that the Brevo breach of early September has a longer guest list than anyone first thought.
If you are a Waltio user, your tax reports are fine. Your email address may not be. And in crypto, an email address in the wrong hands is not a small thing.
Compare crypto tax toolsWhat Did Waltio Actually Tell Its Users?
The notice, sent in French under the heading "Information relative à la sécurité de vos données personnelles", sets out four points.
- First, no malicious emails went out from Waltio's account. Nothing was blasted to the contact list pretending to be Waltio.
- Second, Brevo's analysis is still running. Brevo has not been able to confirm whether the intruder actually viewed or exported Waltio's contact list, only that unauthorised access to the account happened.
- Third, the data at risk is thin. The only fields Waltio keeps inside Brevo are the email address tied to your Waltio account and, if you entered it voluntarily, your French department number. That is the two digit administrative region code used in France, so 75 for Paris, 13 for Bouches du Rhône, and so on. Useful for regional tax messaging, and not much else on its own.
- Fourth, the blast radius stops at Brevo. Waltio says the tool holds no passwords, no API keys, no wallet addresses, no transaction history and no tax data. Logins and connected exchanges are untouched. Waltio also notes that Brevo now treats the incident as closed.
How Big Was The Brevo Breach?
Bigger than one French startup. Brevo said an attacker got into around 120 to 138 customer accounts on 9 and 10 September before access was cut off. The company later attributed it to an authorisation flaw in its login and single sign on layer rather than a classic password leak, which meant the attacker could reach every organisation the compromised invited users were entitled to see.
Brevo's own breakdown split the damage three ways: a handful of accounts were used to send phishing, several dozen had contact lists exported, and the large majority showed no activity at all. Waltio's "analysis in progress" language suggests it is sitting somewhere between the second and third bucket, and does not yet know which.
The names already confirmed are a who's who of crypto: Trezor, BitBox, CoinTracking and Solana Mobile. Trezor got the worst of it. Roughly 347,000 newsletter subscribers received a fake security alert about an STM32 entropy vulnerability, pointing to an app that asked for their wallet backup. Trezor killed the domain at DNS level within twenty minutes, but around 2,500 people had already clicked.

Why Does This Matter More For Waltio Than For Other Brevo Clients?
Because Waltio has been here before, and much worse.
In January 2026 the platform suffered a genuine intrusion into its own systems, not a vendor's. Attackers exfiltrated data tied to tax report generation, contacted the company demanding a ransom, and the Paris prosecutor's cybercrime unit handed the investigation to the Gendarmerie's national cyber unit. Waltio confirmed that email addresses, aggregated crypto balances and tax report data had been exposed, while passwords, API keys, wallet addresses and banking details had not. A file circulating on Telegram afterwards was reportedly used to target French crypto holders directly.
That history changes the maths on this new incident. A standalone email address is low value. An email address that can be cross referenced against a leaked file showing roughly how much crypto you hold is a targeting list. France has had a grim run of kidnappings and home invasions aimed at crypto holders, and those cases start with exactly this kind of data stitching.
So the correct reading of the Waltio notice is not "nothing happened". It is "one more identifier of yours may now be in circulation, and you should assume the attackers are patient".
How Do You Spot A Waltio Phishing Email?
The Brevo attack worked precisely because the phishing came through legitimate infrastructure. Sender domain checks, DKIM, SPF, the usual tells, all of it looked correct on the Trezor emails. So domain inspection alone will not save you here.
Judge the ask instead:
- Any message asking for your seed phrase or wallet backup is fraud. Always. Waltio states plainly that it will never ask for a seed phrase, a password or a transfer of funds, by email or by phone.
- Any message pushing you to download an application to "fix" or "verify" something is fraud.
- Any message creating a deadline, a legal threat or a tax penalty scare is worth a second look. Tax angles are the obvious hook for a Waltio user list.
- Never click through from the email. Type waltio.com yourself, or contact support directly at hello@waltio.com.
Compare hardware walletsWhat Should Waltio Users Do Right Now?
Nothing dramatic, but a few things are worth doing this week.
Turn on two factor authentication on your Waltio account and on every exchange it connects to, using an authenticator app rather than SMS. Review and revoke any exchange API keys you no longer use, and confirm the ones you keep are read only. Change your Waltio password if you have reused it anywhere else. Consider running your address through a breach checker to see what else about you is already public.
And the boring one that actually matters: reduce how much you talk about your holdings, on social media and off it. Data leaks like this one are only the first step. The value is in combining them.
One structural note is hard to avoid. Crypto tax tools sit on the richest dataset in the entire ecosystem, a complete picture of who owns what and where it sits. DAC8 reporting obligations across the EU are pushing more of that data into more places, not fewer. The Waltio notice is a reminder that the weakest link is rarely the platform itself. It is the newsletter tool bolted onto the side of it.
Keeping your keys off the internet entirely is still the strongest answer to any phishing campaign. The CryptoTicker shop stocks hardware wallets at shop.cryptoticker.io.
Related articles
- Crypto Phishing After a Data Breach: The Warning Signs in a Fake Exchange Email
- SafePal Data Breach: 39,798 Customers Exposed With Names, Addresses and Phone Numbers
- Trezor Hack Scare: That STM32 Entropy Email Is a Phishing Attack
- Trezor Data Breach: First 13,689 Customers, Then Roughly 67,000 More Exposed
- Trezor Data Breach: Am I Affected and What Should I Do Now?
Which topics should we dive deeper into?
Select what genuinely interests you. Your picks feed directly into our editorial planning.
Crypto news that's actually worth your time.
Weekly. 60 seconds. Carefully curated by our editors: no hype, no promo flood, no spam.
September 10, 2026 1:14 PM

Phishing Email From the Real Sender Address: How to Check a Wallet Security Warning
An alleged security warning to wallet customers travelled through the manufacturer's genuine sending channel and passed every technical authenticity check. The test that still holds costs you four minutes.
August 25, 2026 10:31 PM

Crypto Wallet Phishing by Letter: Why the QR Code From Your Postbox Wants Your Recovery Phrase
Letters carrying a QR code urge a supposedly urgent wallet update on grounds of quantum resistance and lead to a page that asks for the recovery phrase. The Federal Office for Cybersecurity reported the ploy on August 18, 2026.
December 22, 2020 3:49 PM

Crypto Wallet Provider Ledger Hacked: Data Leak Results in Phishing Scams
Ledger, a cryptocurrency wallet provider has encountered a data breach. The official Twitter account of the hardware wallet tweeted that they have been alerted to the dump of a client database.
September 5, 2026 10:24 PM

Fake German Finance Ministry Letters: Why Nobody May Demand 19 Percent VAT on Your Crypto Purchase
Since September 1, 2026, Germany's Federal Ministry of Finance has been warning about forged letters that demand 19 percent VAT on cryptocurrency purchases while citing real transactions. That tax does not exist, and this is how to spot the forgery.
August 23, 2026 4:36 PM

Operation ASTERIX: How a Fake Support Call Delivers a Counterfeit Wallet App
Security researchers analysed an open server on which a phone system, phishing interfaces and cloned wallet programs all came together. The largest list of numbers was the German one.
August 22, 2019 9:55 AM

Here’s why you should skip Facebook’s Crypto: Instagram Data Breach
It’s practically similar to stating the sky is blue yet we have another Facebook Data Leak close by influencing a huge number of clients. This time around, it includes the contact data of in excess of 49 million Instagram Accounts […]
September 4, 2026 10:26 PM

Pocket Bitcoin Data Breach: When Name, Home Address and Bitcoin Address Circulate Together
The Swiss Bitcoin service Pocket Bitcoin closed its investigation on September 3, 2026: 5,411 people affected, and for 291 of them the Bitcoin addresses they used along with copies of identity documents. Why this one data pairing has lasting effect, and what you should check with your own provider.
November 19, 2018 12:11 PM

Brazilian Crypto Investment Platform Atlas Quantum Hacked, Data Of 264,000 Users Leaked
Atlas Quantum, Brazilian crypto investment platform has been hacked and the data of more than 264,000 of its customers has been leaked.
April 25, 2026 9:55 AM

France Crypto Kidnappings Crisis: Pavel Durov Blasts Data Leaks and New Surveillance Laws
Pavel Durov exposes a surge in crypto-related kidnappings in France, blaming tax data leaks and warning against new social media surveillance laws.
September 12, 2026 4:12 PM

Revolut Data Breach: Am I Affected, and What About My Bitcoin History?
After a forged government request, Revolut handed identity documents, account statements and complete Bitcoin transaction histories to an unauthorised party. Here is how to establish whether you are affected, and which protective measure actually achieves anything in this case.
May 4, 2019 5:44 PM

Microsoft Hackers Stole Crypto Using Victims Emails
Another batch of crypto users have lost money recently through an unlikely breach. Recently, Microsoft services such as Hotmail, MSN, and Outlook have been hit by a breach. It was later learned that the breach was due to an employee’s […]
September 28, 2026 10:26 AM

Phantom Wallet and Solscan: What a Solana Transfer Really Costs and Where It Fails
A transfer on Solana costs 0.000005 SOL, a new token account ties up 0.00148844 SOL once — both values measured on-chain by us today. This practical guide shows how to set up Phantom, how to get there from the exchange, how to read Solscan and what applies for tax in Germany.
August 14, 2026 6:18 PM

Bitcoin From a Foreign Exchange to Austria: Which Tax Data You Need
Transferring Bitcoin from a foreign exchange to an Austrian platform: which tax data can be missing for the withholding tax. And what investors need to watch out for.
September 14, 2026 1:27 PM

Bitcoin Lost to a Scam: What Counts as a Tax Loss in Austria
Lost bitcoin to a scam? Why Austria generally does not recognise the damage as a tax loss for privately held assets, and when compensation payments start to matter.
September 1, 2026 1:25 PM

Bitcoin Tax Report Wrong: What Austrian Investors Can Do
Errors in a Bitcoin tax report are not unusual. This is the data Austrian investors should check, and how a wrong capital gains tax deduction is put right.
August 21, 2026 1:33 PM

Bitcoin With No Cost Basis: How Austria Taxes the Sale
Bitcoin purchase price no longer provable? How Austria works out the capital gains tax, when a flat-rate cost basis applies and what investors can do.
May 26, 2025 11:00 PM

Inside Bitget: How COO Vugar Usi Zade Is Shaping the Future of Crypto Trading
From Bitget Seed and AI-powered tools to regulatory strategy and mass adoption, COO Vugar Usi Zade reveals how Bitget is building the next era of crypto trading.
August 11, 2026 1:32 PM

How to Store a Seed Phrase Safely: What Steel, a Passphrase and Multisig Do for Your Wallet Backup
The Coldcard case pushed the manufacturer question to the front, while barely touching on where the backup is kept. This guide places paper, steel, the passphrase and splitting methods against the BIP-39 and SLIP-0039 standards.
September 25, 2026 10:31 AM

BaFin Warning: What Happens When You Enter Your Data on an AI Crypto Platform
On September 23, 2026 BaFin warned about 39 near-identical websites presenting themselves as AI-powered crypto trading platforms. On its findings these pages take no money but pass the data left in their contact form on to unauthorized trading platforms.
August 19, 2026 1:31 AM

Crypto Tax Software Compared: What Blockpit, Divly, Waltio and Coinpanda Charge for One Tax Year
On August 14, 2026 we retrieved thirteen pricing pages from providers of crypto tax software and set the four evaluable ones with a German focus side by side. The comparison shows why three of them charge the same price at 1,000 transactions and where the expensive difference really lies.
September 29, 2026 1:15 AM

BaFin warns over nova-c-solutions.com: What is behind a genuine registration number
The BaFin has warned about a website offering crypto-asset services without authorisation and speaks of a presumed identity theft at the expense of a real US company. The case shows why the advice to look a provider up in the register does not carry on its own.
August 11, 2026 9:18 AM

Your Crypto Exchange Is Telling You to Withdraw: How to Spot Phishing After the MiCA Deadline
Unauthorised crypto providers now have to tell their EU customers to withdraw, which leaves fraudsters an easy run with faked requests. Here is how to check in two minutes whether the message is genuine.
August 23, 2026 1:16 PM

Address Poisoning: Why Seven of Forty Characters Were Enough to Divert $2 Million
A fake wallet address matched the real one in just seven of forty characters and still intercepted 2 million USDC. Our own count of the affected wallet shows that a third of all counterparties in its history belong to such look-alikes.
September 23, 2026 4:12 AM

How to Set Up a Crypto Wallet: Securing Your Coins in Seven Steps
Your own crypto wallet is set up in twenty minutes, yet a single step decides everything that follows. This guide takes you through wallet type, recovery words and the test amount, and sets out what BaFin and the tax office expect.
September 19, 2026 10:11 PM

North Korean Hackers Drain 7,000 Crypto Wallets: What to Check on Job Offers and Coding Tests
Seven agencies, among them Germany's BND and BfV, warn about the WaterPlum group: 30,000 infected machines, more than 7,000 drained wallets. The bait is a job offer, the trap a coding test.
September 17, 2026 4:14 PM

D'CENT App Wallet: How to Tell If Your Recovery Phrase Has to Move Now
Manufacturer IoTrust reports suspicious asset transfers in the D'CENT app wallet and asks users to move their holdings. One question decides the matter: has your recovery phrase ever been entered into the app?
September 14, 2026 10:11 PM

Revolut Data Breach: Your Files Are Public, and Here Is What You Can Do
Since September 14, the ID copies, KYC selfies and account statements stolen from Revolut have been published. What a password change no longer achieves, which rights the GDPR gives you, and why your Bitcoin history is the most sensitive part of the package.
More from CryptoTicker

