Trezor user reports new wave of phishing

cryptonews.ruPublicado em 2026-08-26Última atualização em 2026-08-26

Resumo

A Trezor user reported receiving a phishing email disguised as a message from the hardware wallet provider. The fake email claimed there was a critical entropy vulnerability in the firmware, alleging that a 2021 update could have weakened the seed phrase generation on some devices. Trezor acknowledged this new wave of phishing attacks, stating that attackers are likely using a combination of data from past leaks at various cryptocurrency services, which may include compromised KYC information. The company referenced a prior security incident involving a third-party tool and mailing list subscriber emails as a possible link. Trezor also noted it has taken measures to prevent further data leaks. This follows a recent report from Trezor about a data breach affecting 13,689 customers due to a hack at its logistics partner, ShipMonk, approximately two weeks earlier.

X user under the pseudonym x3ideRaven reported receiving a phishing email disguised as a message from Trezor. According to him, he purchased a device the day after the company's reported data breach period, but still started receiving fraudulent messages.

The fake email claimed to be about a supposed "critical entropy vulnerability in the firmware." The attackers alleged that a bug in a 2021 update could affect seed phrase generation on some devices.

Specifically, the email claimed that due to a configuration error, vulnerable firmware versions could use a non-cryptographic pseudorandom number generator instead of a hardware true random number generator. Supposedly, this could reduce the seed phrase entropy from 128 to 40 bits.

Trezor stated that they are aware of the new wave of phishing.

"We have confirmed that attackers are using a combination of data from different database leaks at several cryptocurrency services. It is quite possible that some KYC data may have been compromised, and the attackers are now trying their luck," the company noted.

The team reminded about a previous security incident related to a third-party tool and mailing list subscriber email addresses. Company representatives suggested this case could be linked to the current phishing campaign.

Trezor also added that they have already taken measures to prevent further leaks.

Recall that approximately two weeks prior to this report, Trezor announced a leak of customer personal data due to a hack of their logistics partner ShipMonk. The incident affected 13,689 buyers.

end-content

Perguntas relacionadas

QWhat is the main topic of the article?

AThe article discusses a new wave of phishing emails targeting users of the Trezor hardware wallet, where attackers are impersonating the company to send fraudulent security alerts.

QWhat vulnerability did the phishing email claim to be warning users about?

AThe phishing email claimed to warn about a 'critical entropy vulnerability in the firmware,' specifically that a bug from a 2021 update could have affected seed phrase generation, potentially reducing entropy from 128 to 40 bits by using a non-cryptographic pseudorandom number generator.

QHow did Trezor explain the source of the phishing targets' contact information?

ATrezor stated that the attackers are likely using a combination of data from different database leaks across multiple cryptocurrency services, and that some KYC data may have been compromised.

QWhat previous security incident did Trezor mention in relation to this phishing campaign?

ATrezor mentioned a previous security incident involving a third-party tool and email addresses of newsletter subscribers, suggesting it might be related to the current phishing campaign.

QWhat other recent data breach was mentioned in the article that affected Trezor customers?

AThe article mentions that approximately two weeks prior, Trezor reported a leak of customer personal data due to a hack of its logistics partner, ShipMonk, which affected 13,689 buyers.

Leituras Relacionadas

Circle CEO: Stablecoins Are at the Internet's 2002 Stage, Will Reach Trillions of Dollars in the Future

Circle CEO Jeremy Allaire, in a Q2 2026 earnings AMA, discussed the current state and future of stablecoins and Circle's strategy. He compared stablecoins today to the internet in 2002, predicting they will grow from hundreds of billions to trillions of dollars. Key points include: * **Current Use Cases**: Stablecoins have achieved product-market fit in digital asset markets (for trading/settlement), as a digital dollar store of value in emerging markets, and for cross-border payments and settlement. * **Future Growth Areas**: Allaire highlighted opportunities in the AI agent economy, merchant payments (especially via QR codes and stablecoin cards), and the convergence of traditional and on-chain finance. * **Circle's Strategy**: Circle aims to grow USDC through global partnerships. Its economic engines will include reserve income, transaction fees from its on-chain payment network (CPN), and its upcoming "economic operating system," Arc. * **Arc's Vision**: Arc, launching its mainnet on September 16, is a stablecoin-native blockchain designed for seamless user and developer experience. It aims to power the future "on-chain" economy where businesses and AI agents operate. * **Global Adoption**: Allaire emphasized that stablecoin adoption is a global phenomenon, driven by regulatory clarity in regions like Europe (MiCA) and the US (GENIUS Act), and will continue regardless of specific US legislation like the CLARITY Act. * **EURC Growth**: Circle's euro stablecoin, EURC, has surpassed €400 million in circulation, benefiting from early preparation for European regulations and existing distribution networks. Allaire expressed confidence in Circle's execution, citing strong team cohesion and the adoption of AI tools, while identifying cybersecurity and global local operations as key areas for continued strengthening.

marsbitHá 45m

Circle CEO: Stablecoins Are at the Internet's 2002 Stage, Will Reach Trillions of Dollars in the Future

marsbitHá 45m

With Revenue 3.8 Billion Lower Than CXMT, Net Profit Is 8.6 Billion Higher: What Secrets Are Hidden in YMTC's IPO?

Chinese NAND flash giant Changcun Holdings has submitted its IPO prospectus to the Shanghai Stock Exchange. In Q1 2026, the company reported revenue of 47.042 billion yuan and a net profit attributable to parent company shareholders of 33.379 billion yuan. This presents a striking contrast with its competitor Changxin Technology, which had higher revenue (50.8 billion yuan) but a significantly lower net profit of 24.762 billion yuan. The key to this discrepancy lies in their ownership structures of core assets. Changcun Holdings fully owns its main operating entity, Yangtze Memory Technologies Co., Ltd., allowing nearly all group profits to flow to the parent company. In contrast, Changxin Technology controls but does not fully own its key production subsidiaries, meaning a substantial portion of its consolidated profits (approximately 8.25 billion yuan in Q1 2026) belongs to minority shareholders, reducing its reported net profit. Despite Changcun's higher net profit, its pre-IPO valuation is estimated lower than Changxin's. Analysts attribute this to differing market expectations: Changxin, focused on DRAM and the high-growth HBM market for AI servers, is seen as having greater long-term growth potential. Changcun, while dominant in NAND flash, operates in a market with inherent size constraints, making its future valuation more dependent on successfully upgrading its product mix toward higher-value segments like enterprise SSDs.

marsbitHá 56m

With Revenue 3.8 Billion Lower Than CXMT, Net Profit Is 8.6 Billion Higher: What Secrets Are Hidden in YMTC's IPO?

marsbitHá 56m

Perpetual Contract Liquidation Wave Resurges, Bitcoin $62k - $67k May Become the 'Disaster Zone'

A wave of liquidations has hit the crypto perpetual futures market, with analysts warning of continued volatility. Following Bitcoin's drop below $76,000 and subsequent rebound, over $84 million in long positions were liquidated in one hour, demonstrating the amplified impact of leverage. The U.S. CFTC's recent approval of a spot Bitcoin perpetual contract on the Kalshi exchange has opened this "previously closed" asset class to American institutions, with the platform reporting $5.5 billion in volume in its first two weeks. However, critics like Better Markets warn that perpetuals are "among the most dangerous crypto products" for retail investors due to a lack of enhanced protections. Recent price action saw a massive $529 million in hourly liquidations, predominantly longs. Analysts note that while a $3.3 billion short squeeze cleared liquidity above $80,000, a significant pool of long liquidations now sits between $62,000 and $67,000, posing a downside risk if key resistance holds. Experts caution new traders against using leverage or options, which can expire worthless, without proper experience and risk management. Despite the dangers, the demand for leveraged products persists, with some institutional players preferring on-chain platforms for their transparency and self-custody. As Kalshi expands its perpetual offerings beyond crypto, the core warning remains: leverage can lead to sudden, severe losses for unprepared investors.

marsbitHá 57m

Perpetual Contract Liquidation Wave Resurges, Bitcoin $62k - $67k May Become the 'Disaster Zone'

marsbitHá 57m

Trading

Spot
活动图片