Update (September 22, 2026): Phishing email sent in CoinTracking's name
On September 9, some CoinTracking users received an email with the subject “Data Breach Notice: Please refresh API Keys as soon as possible”. If you received this email, here is what matters most: CoinTracking's systems were not compromised.
The incident occurred at Brevo, an external email delivery provider. Brevo does not hold CoinTracking passwords, API keys, portfolio data or transaction data. Brevo's security team conducted a thorough investigation and found that the attacker did not export any CoinTracking email addresses. If any new findings emerge as the investigation continues, we will inform you immediately.
The attacker used access to several customer accounts to send the emails through Brevo's legitimate infrastructure. As a result, the phishing emails passed the usual authentication checks and were harder to recognize as phishing.
If you only received the email and did not enter any information, no action is required. If you entered your CoinTracking password, change it and enable 2FA. Any API keys entered should be revoked and replaced directly through the relevant exchange.
Immediately after the incident, CoinTracking changed passwords, deleted existing Brevo API keys and secured affected access points.
If you receive a suspicious email with a link, don't click it. Go directly to the platform and check there whether any action is required.
If you received an email titled “Data Breach Notice: Please refresh API Keys as soon as possible”, that email was not sent by CoinTracking. It is a phishing attempt.
Your CoinTracking account is not affected
The email was sent through an external email service provider that we use to deliver messages. The incident was limited to that service – not to CoinTracking's own systems.
That service holds no passwords, no API keys and no portfolio or transaction data. Your account, your login details and your connected exchanges remain secure.
Based on current information, email addresses held by that provider may have been accessed during the incident. In practice this mainly means: please be especially attentive over the coming weeks to emails that appear to come from us.
What you should do
For the vast majority of recipients, no action is needed. If the email is still in your inbox:
- Do not click any links in it.
- Do not enter your CoinTracking login details or API keys on any page it links to.
- Delete the email.
If you already entered information
Only in that case are two steps worth taking:
- Change your CoinTracking password and enable two-factor authentication if you have not already.
- If you entered exchange API keys, revoke and regenerate them directly at the exchange that issued them – never through a link in an email.
Current status
The access route used to send these emails has been closed, and the links contained in the messages have been deactivated. We have reviewed our own systems and found no indication of any access.
Our email service provider, Brevo, has documented the incident in a public statement.
CoinTracking is certified under ISO 27001 for information security. If you have any questions, you can reach us any time at support@cointracking.info.
Last updated: September 22, 2026