Trezor Initiates Investigation as Phishing Campaign Targets Crypto Hardware Wallet Users
Source: Pixabay Trezor, a cryptocurrency hardware wallet company, is currently investigating a potential data breach due to an ongoing email phishing campaign. On October 26, the anonymous blockchain investigator ZachXBT...
Archive context
Older archive item. Useful for background and entity history, but not a fresh market-moving signal.
Source: Pixabay
Trezor, a cryptocurrency hardware wallet company, is currently investigating a potential data breach due to an ongoing email phishing campaign.
On October 26, the anonymous blockchain investigator ZachXBT reported a phishing attack targeting Trezor users via his Telegram channel. ZachXBT cited a post on X (formerly Twitter) from the account JHDN, which raised concerns that Trezor might have experienced a breach.
It looks like Trezor may have been breached? @Trezor @zachxbt #Trezor pic.twitter.com/4lmjZE1Quk
— j (@JHDN) October 26, 2023
These concerns were based on the receipt of phishing emails sent to the specific email accounts used for purchasing Trezor wallets, suggesting a potential compromise of user data.
Users reported receiving phishing emails encouraging them to install an app from the domain’ trezor.us,’ which is different from the official ‘trezor.io’ domain.
Trezor is investigating the extent of the breach, and until further notice, users are advised not to click on links from unauthorized sources to safeguard their security. Trezor’s brand ambassador, Josef Tetek, confirmed the awareness of the phishing campaign and outlined the company’s ongoing efforts to combat such threats.
Trezor actively reports fake websites, contacts domain registrars, and educates users on the potential risks associated with phishing attacks.
“Users should never enter their recovery seed directly into any website or mobile app or type it into a computer. The only safe way to work with the recovery seed is as per the instructions shown on a connected Trezor hardware wallet.”
In a previous blog post from 2022, Trezor highlighted the modus operandi of a phishing email scam. Typically, these scams involve users clicking on a link in the email, which directs them to a fraudulent Trezor Suite app. This fake app then prompts users to connect their wallet and input their seed. Once the seed is entered into the app, it becomes compromised, enabling the attacker to swiftly transfer funds to their wallet.
While hardware wallets like Trezor are known for their security features, phishing remains a significant threat in the cryptocurrency space, as it can deceive users into compromising their wallets or private keys.
Crypto Community Faces Rising Threat of Phishing Attacks as Trezor Issues WarningsTrezor has battled many phishing attempts over the years. The company maintains a real-time blacklist of scam sites and guides users on identifying frauds. It has also warned its users in the past about a new phishing attack targeting their crypto investments by trying to steal their private keys.
Early this year, Trezor took its X account to caution users about an active phishing attack designed to steal investors’ money by making them enter the wallet’s recovery phrase on a fake website. However, it is not only Trezos that is combating phishing. According to some cybersecurity reports, the number of cryptocurrency phishing attacks saw a 40% increase in 2022.
In 2020, rival hardware wallet firm Ledger suffered a massive data breach, with attackers publicly exposing the personal information of more than 270,000 Ledger customers. Also in September, a crypto whale fell victim to a massive phishing attack, losing millions of dollars in staked Ether on the liquid staking provider Rocket Pool.
The investor lost their entire address balance of Lido Staked ETH (stETH) and Rocket Pool ETH (rETH). At the time of the attack, the amount stolen was worth $15.5 million in stETH and $8.5 million in rETH, a staggering $24 million combined.
Cryptocurrency investors have been suffering from multiple phishing attacks, despite many efforts to curb such scams.
The post Trezor Initiates Investigation as Phishing Campaign Targets Crypto Hardware Wallet Users appeared first on Cryptonews.
Why this matters
This security story adds another data point to the current market tape and is useful when read alongside nearby source coverage.
Original source
Read on CryptonewsRelated market context
SafePal Data Breach Exposes 39,798 Crypto Customers, Wallet Keys Remain Secure
Key Takeaways: About 39,798 users’ personal and purchase information were disclosed via a flaw in an order tracking plugin, accord...
Bitcoin purchases halted after data breach puts 250,000 crypto users at risk
Israel’s largest regulated cryptocurrency broker, Bits of Gold, is investigating a data breach that potentially exposed the person...
Bits of Gold Breach May Expose 200,000 Crypto Users, But Funds Remain Safe Online
Key Takeaways: A data breach at Bits of Gold could affect up to 200,000 customers. No exposure of customer funds, crypto assets, p...
SafePal Bitcoin Wallet Data Breach Stokes Fears of Physical Attacks
A flaw in an order-tracking plug-in of bitcoin wallet provider SafePal exposed names, addresses and phone numbers of nearly 40,000...
CyberWallet users have until Aug. 15 before crypto withdrawals become a smart contract recovery job
Crypto company Cyber is telling CyberWallet and Cyber Passkey Wallet users to move their assets ahead of an Aug. 15 shutdown that...
Crypto wallet SafePal reveals a data breach exposing nearly 40,000 customers' order info
While the data breach exposed the personal order details of thousands of customers, all private keys, seed phrases, and crypto ass...