💸 Trezor's problem isn't Trezor
Hardware wallet maker Trezor has warned customers twice in under two months about data breaches — both times through third-party vendors, not Trezor's own systems.
The latest: hackers hit Brevo, a marketing platform, and sent ~347,000 phishing emails titled "Critical Security Alert." The link leads to a fake app requesting your wallet recovery phrase — share it and the funds are irreversibly gone.
Before that, logistics partner ShipMonk leaked names, phones, and home addresses of 81,000 customers. Some have since received physical mail with phishing QR codes. Physical addresses also raise the risk of "wrench attacks" — extracting passwords by force.
The wallets are untouched. As TechCrunch notes: a solid product held — its ecosystem didn't.
Post #3661
2.17K
