Trezor told Cointelegraph that the phishing email was sent to 347,000 subscribers and said it is treating every address as “known to the attacker and possibly reusable for phishing.” An attacker exploited a flaw in email platform Brevo’s login system to access 138 client accounts, enabling a phishing email to reach roughly 347,000 Trezor newsletter subscribers and similar fraudulent messages to be distributed through accounts belonging to hardware wallet maker BitBox and crypto portfolio tracking and tax-reporting platform CoinTracking. In a Thursday postmortem, Brevo said six accounts were used to send phishing emails, contacts were exported from 43 and 93 accounts showed no meaningful activity. The platform did not specify whether the categories overlapped. The attacker created a Brevo account, enabled single sign-on and invited legitimate Brevo users into the configuration. Brevo said access should have been confined to that organization, but an authorization boundary failed and granted access to every or...
BitBox said multiple Bitcoin companies appeared to have been targeted through a shared newsletter provider, while Trezor confirmed a breach at its email service. Hardware wallet makers Trezor and BitBox warned users about phishing emails disguised as urgent security notices after suspected compromises involving third-party email services. On Wednesday, Trezor said its email provider had been breached and warned that a message titled “Critical Security Alert: STM32 Entropy Vulnerability” was fraudulent. The company urged recipients not to click any links. On the same day, Bitbox warned users about a phishing email pretending to come from the company. The company said its preliminary review indicated that its newsletter provider was likely compromised, adding that multiple Bitcoin companies appeared to have been targeted through a shared provider. Read more
Trezor said an additional 67,000 US users were affected by its shipping provider’s data breach, opening the path to potential phishing attacks and social engineering scams. The impact of hardware wallet provider Trezor’s data breach was larger than initially estimated, expanding to an additional 67,000 US customers. The breach may endanger more US users who ordered between November 2019 and August 2021, Trezor said in a Friday X post, citing the latest update from its shipping provider, ShipMonk. These customers had their full details exposed, including name, email, number, shipping address and order specifics. Trezor blamed the shipping provider for not deleting the data from these orders, despite saying it had received written assurances from ShipMonk. Read more
The wallet provider warned that thousands of users could potentially be at risk of phishing attempts, while advising that all devices, private keys and backups were safe. Cryptocurrency wallet company Trezor reported a breach of personal data affecting about 14,000 users through its shipping provider, ShipMonk. Trezor’s Wednesday blog post said users who received its products from the US, UK, Sweden, Colombia, Brazil, Italy, and Portugal between May 10 and Aug. 8 were at risk from potential phishing attacks using their personal information. The company reported that 11,742 customers could have had their name, physical address, phone number, and email address compromised, while 1,947 users potentially had their name, city, and email address breached. “To be clear, our systems were not compromised, and your Trezor device is secure, but the affected customers might be targeted by more sophisticated phishing attempts,” said the company. “Scammers can use the leaked information to send fake emails, make fake phon...
Trezor and Tropic Square disclosed a TROPIC01 chip vulnerability found during a Ledger Donjon audit, saying the Safe 7 wallet and user funds remain secure. Hardware wallet company Trezor and chipmaker Tropic Square have disclosed a vulnerability in one of the secure elements used in Trezor Safe 7 hardware wallet, saying the flaw does not put user funds at risk because the chip alone cannot expose a wallet. The vulnerability was identified during an independent security audit conducted by Ledger Donjon, the security research team at rival hardware wallet maker Ledger, according to a Trezor statement. Tropic Square provided the affected TROPIC01 Secure Element chip to the Ledger Donjon team for an independent audit. The companies said compromising TROPIC01 alone would not be enough to access a user’s wallet, PIN or funds. Read more
The feature lets users earn stablecoin yield directly through Trezor Suite without connecting external wallets or using separate DeFi apps. Trezor has integrated native stablecoin yield functionality into Trezor Suite, the hardware wallet provider’s desktop and mobile application, in a move that could make earning yield on stablecoins more accessible to users who have traditionally avoided decentralized finance due to its complexity and security risks. Announced on Thursday, the feature comes through an integration with Morpho, a decentralized lending protocol built on Ethereum. The integration allows users to deposit USDt (USDT) and USDC (USDC) into pre-selected Morpho vaults directly through Trezor Suite without connecting external wallets or using separate DeFi applications. According to Trezor, deposits, withdrawals and reward claims are signed directly on users’ hardware wallets through the company’s clear-signing interface, which displays transaction details in human-readable form on the device screen. ...
Cointelegraph takes a look at the latest devices from Ledger and Trezor, two long-time leaders in self-custody hardware wallets. Major hardware crypto wallet providers Ledger and Trezor have both released new wallet iterations, giving users additional options to safeguard their assets through self-custody. Paris-based Ledger introduced its latest device, the Ledger Nano Gen5, on Thursday. In a notable shift, the company has dropped the term “hardware wallet” entirely, now referring to all its devices as “Ledger signers.” Rival hardware wallet company Trezor, based in Prague, also released its Trezor Safe 7 earlier this week, describing the device as its first quantum-ready hardware wallet. Read more
Trezor warned of ongoing phishing attempts exploiting its support contact form. Hardware wallet producer Trezor warned users about an ongoing phishing campaign that mimics the company’s official customer support replies. In a Monday X post, Trezor warned that the firm is aware “attackers abused our contact form to send scam emails appearing as legitimate Trezor support replies.” The company reminded its customers not to share wallet backups, noting that they should always be kept “private and offline.” Trezor said it “will never ask for your wallet backup,” confirming that the emails may appear as legitimate but are not. Read more