Hackers target Trezor crypto wallet users after mailing list got compromised

cryptoslate2022-04-05 tarihinde yayınlandı2022-04-05 tarihinde güncellendi

Özet

Hardware cryptocurrency wallet manufacturer Trezor has divulged that its customers are being targeted by so-called “phishing” attacks after Mailchimp.

Hardware cryptocurrency wallet manufacturer Trezor has divulged that its customers are being targeted by so-called “phishing” attacks after Mailchimp, the firm’s email automation service provider, was “compromised by an insider targeting crypto companies.”

“We are currently investigating how many customers might have been affected following an insider compromise of a newsletter database hosted on Mailchimp,” Trezor wrote in a blog post today, adding:

“The Mailchimp security team disclosed that a malicious actor accessed an internal tool used by customer-facing teams for customer support and account administration. The bad actor gained access to this tool as a result of a successful social engineering attack on Mailchimp employees.”

Keep your app close, keep your seed phrase closer

Further, the attacker is specifically targeting crypto-related companies, Trezor noted. As a result, its wallet users began receiving phishing emails on Sunday, April 3, asking them to click a link that leads to the download page for a “Trezor Suite lookalike app.”

A copy of the phishing email. Image: Trezor
A copy of the phishing email. Image: Trezor

A copy of the phishing email. Image: Trezor

If an unsuspecting user falls into this trap, the malicious app then asks for their seed phrase—basically the private key that gives the perpetrators full access to their crypto holdings. Once entered, the seed gets compromised and users’ funds are immediately transferred to the attackers’ wallet.

“This attack is exceptional in its sophistication and was clearly planned to a high level of detail. The phishing application is a cloned version of Trezor Suite with very realistic functionality, and also included a web version of the app.”

Luckily, since potential victims have to actually install the malware on their devices (although there is also a web version), contemporary operating systems should alarm them about its unknown source. “This warning should not be ignored, all official software is digitally signed by SatoshiLabs,” Trezor pointed out.

Stay vigilant

According to Trezor, the firm has already shut down the phishing domain. However, if some users have entered their seed phrases after all, they should immediately move their crypto to a newly generated address (unless it’s already too late, of course).

“If you have not received such an email, there is still a chance your email address has been leaked, so it is best to remain vigilant in case a new wave of emails appear. Compromised email addresses may be targeted again in future so please report any new phishing attempts directly to [email protected]

Until this issue is resolved, the wallet manufacturer has ceased any newsletter activity. Additionally, users should “not open any emails appearing to come from Trezor until further notice” and make sure they are using anonymous email addresses for “Bitcoin-related activity,” the firm urged.

İlgili Okumalar

a16z Deep Dive: Stop Chasing the 'AI Smell', Here's a Practical Guide to Writing with AI

"Don't Obsess Over AI Detection: A Practical Guide to Writing Alongside AI" by Steph Zinn (a16z Crypto) This guide moves beyond the flawed premise that AI-generated text can be easily spotted by a set of "tells" and that these features automatically mean poor quality. Instead, it focuses on how writers and founders can use LLMs effectively by understanding, controlling, and editing the common stylistic tendencies of AI-assisted prose. The article breaks down AI writing "tells" into four key dimensions: **1. Rhetorical Features (Insight-Shaped Writing):** AI often produces semantically empty, "corporate-sounding" filler language—vague profundities, hedging phrases, excessive parallelism, and summary statements. The advice is to ruthlessly edit these out, using prompts to make language more specific and direct. **2. Voice Features (The Alexa Voice):** Default AI writing relies on a narrow, fungible vocabulary of low-friction, abstract words and cliché phrases that lack personality. While this generic voice is acceptable for support docs or mass communications, founders should preserve their unique voice for impactful writing. Use LLMs to identify and replace jargon, aiming for concrete, distinctive word choices. **3. Structural Features (Form Without Function):** AI tends towards over-structured text with excessive subheadings, lists, roadmaps, and the rigid "three-point" framework. While clear structure is good for readability and SEO, it shouldn't force ideas into unnatural containers. Choose a structure that serves the format and purpose, borrowing from effective examples. **4. Punctuation Features (Dash Panic):** The overuse of em dashes and colons has become a hallmark, but writers shouldn't avoid useful punctuation just to seem "human." The key is avoiding repetitive, distracting patterns. Use punctuation that is grammatically correct and supports the flow of your argument. The core argument is that many so-called AI flaws are just amplified versions of existing bad writing habits. The goal isn't to eliminate AI's role but to use it as a tool while maintaining editorial control. The final question shouldn't be "Can this be detected as AI?" but "Does this writing effectively do its job?"

marsbit1 saat önce

a16z Deep Dive: Stop Chasing the 'AI Smell', Here's a Practical Guide to Writing with AI

marsbit1 saat önce

İşlemler

Spot
活动图片