Loading prices…
🩸BEARISH

Trezor Breach Exposes 347K Contacts to Phishing

The hardware remained intact, but recovery-phrase reuse and trusted email infrastructure gave attackers paths around the device.

Two recent incidents involving D’CENT and Trezor show that hardware-wallet security can hold while the surrounding software, vendors and customer data create new paths to user funds. D’CENT is investigating unauthorized transfers from its App Wallet, while a breach at Trezor’s marketing provider exposed 347,149 customer email contacts. Neither company has reported a compromise of its hardware-wallet security.

Why it matters

D’CENT’s investigation centers on users who entered recovery phrases into its software wallet and signed transactions on versions earlier than 8.1.0. A phrase generated on a hardware device can recreate the same private keys elsewhere, so importing it into a phone-based wallet extends the risk beyond the device’s secure signing environment. The potential exposure includes Bitcoin, Ethereum, XRP Ledger, Tron and EVM-compatible networks.

Trezor’s incident shows a different route. Attackers exploited a flaw in marketing provider Brevo’s SAML single sign-on system, exported contacts from 43 customer accounts and used six accounts to send phishing emails through trusted infrastructure. Trezor’s exposed list covered 347,149 contacts. About 2,500 recipients reached a malicious domain after receiving a fake hardware-vulnerability alert that requested wallet backups.

Market impact

Clicking the Trezor link alone did not expose funds. The danger began when users entered a recovery phrase into the malicious application, allowing attackers to reconstruct wallets elsewhere. D’CENT likewise said that connecting a hardware device to its app normally does not transfer the phrase to a phone, while manual import does.

The incidents raise the security burden for self-custody providers. Wallet companies must protect not only secure chips and transaction-signing systems, but also customer databases, software workflows and outside vendors. Users who meet D’CENT’s criteria are being advised to update the app, create a wallet with a new recovery phrase and move affected assets. Both cases reinforce the same rule: recovery phrases must remain offline and must never be entered into software or phishing forms.

Related tokens
$BTC $ETH $XRP $TRX

Frequently asked questions

  1. What happened in the D’CENT wallet incident?

    D’CENT is investigating unauthorized transfers from its App Wallet. Its criteria focus on wallets whose recovery phrases were entered into the app and that signed transactions on versions earlier than 8.1.0.

  2. Did either incident compromise a hardware wallet?

    Neither D’CENT nor Trezor has reported a compromise of its hardware-wallet security. The reported risks involved software workflows, phishing and third-party infrastructure.

  3. How did the Trezor breach expose users to phishing?

    Attackers breached Trezor’s marketing provider Brevo, exported 347,149 email contacts and sent a fake hardware-vulnerability alert through trusted email infrastructure. About 2,500 recipients reached the malicious domain.

  4. Why is entering a recovery phrase into software risky?

    A recovery phrase can recreate the same private keys on another device. Importing it into software or entering it into a phishing application can therefore give attackers control without defeating the hardware wallet.

  5. What steps are affected D’CENT users advised to take?

    D’CENT advises users who meet its criteria to update the app, create a wallet backed by a new recovery phrase and transfer affected assets. Recovery phrases should remain offline and should not be entered into software or phishing forms.

Source attribution
Aggregated from CryptoSlate · Verified · Last refreshed 4h ago
Open original →