Hackers target Trezor crypto wallet users after mailing list got compromised

cryptoslate发布于2022-04-05更新于2022-04-05

文章摘要

Hardware cryptocurrency wallet manufacturer Trezor has divulged that its customers are being targeted by so-called “phishing” attacks after Mailchimp.

Hardware cryptocurrency wallet manufacturer Trezor has divulged that its customers are being targeted by so-called “phishing” attacks after Mailchimp, the firm’s email automation service provider, was “compromised by an insider targeting crypto companies.”

“We are currently investigating how many customers might have been affected following an insider compromise of a newsletter database hosted on Mailchimp,” Trezor wrote in a blog post today, adding:

“The Mailchimp security team disclosed that a malicious actor accessed an internal tool used by customer-facing teams for customer support and account administration. The bad actor gained access to this tool as a result of a successful social engineering attack on Mailchimp employees.”

Keep your app close, keep your seed phrase closer

Further, the attacker is specifically targeting crypto-related companies, Trezor noted. As a result, its wallet users began receiving phishing emails on Sunday, April 3, asking them to click a link that leads to the download page for a “Trezor Suite lookalike app.”

A copy of the phishing email. Image: Trezor
A copy of the phishing email. Image: Trezor

A copy of the phishing email. Image: Trezor

If an unsuspecting user falls into this trap, the malicious app then asks for their seed phrase—basically the private key that gives the perpetrators full access to their crypto holdings. Once entered, the seed gets compromised and users’ funds are immediately transferred to the attackers’ wallet.

“This attack is exceptional in its sophistication and was clearly planned to a high level of detail. The phishing application is a cloned version of Trezor Suite with very realistic functionality, and also included a web version of the app.”

Luckily, since potential victims have to actually install the malware on their devices (although there is also a web version), contemporary operating systems should alarm them about its unknown source. “This warning should not be ignored, all official software is digitally signed by SatoshiLabs,” Trezor pointed out.

Stay vigilant

According to Trezor, the firm has already shut down the phishing domain. However, if some users have entered their seed phrases after all, they should immediately move their crypto to a newly generated address (unless it’s already too late, of course).

“If you have not received such an email, there is still a chance your email address has been leaked, so it is best to remain vigilant in case a new wave of emails appear. Compromised email addresses may be targeted again in future so please report any new phishing attempts directly to [email protected]

Until this issue is resolved, the wallet manufacturer has ceased any newsletter activity. Additionally, users should “not open any emails appearing to come from Trezor until further notice” and make sure they are using anonymous email addresses for “Bitcoin-related activity,” the firm urged.

你可能也喜欢

卡尔达诺创始人霍斯金森称“将短暂离开”:事情始末

卡尔达诺创始人查尔斯·霍斯金森在6月2日一场气氛紧张的直播后,于X平台突然宣布“要休息一下”。他质疑自己在卡尔达诺去中心化治理体系内,面对项目失败和资金争议时实际拥有的权力。 此次表态的背景是,生态内知名数据分析平台TapTools因核心人员离职和运营成本上升而宣布将逐步关停。霍斯金森在直播中警告,今年下半年卡尔达诺DeFi领域可能面临更多压力,会有更多dApp消亡并出现整合。他强调,自己常因ADA市场价格和生态挫折受到指责,但实际上对国库资金、协议升级或品牌基础设施并无直接控制权。霍斯金森指出,生态发展和治理所需的资金被分配给了独立的实体,而非他个人,他本人没有治理密钥、无法发起硬分叉、也无法动用国库。 这一事件凸显了卡尔达诺当前治理阶段的深层矛盾:其治理体系旨在将控制权从创始实体移交给ADA持有者和社区代表,这在赋予社区正式权力的同时,也可能在关键生态公司面临压力时难以进行紧急协调。此前,卡尔达诺基金会关于2026年峰会的资金提案因未达到三分之二批准门槛而被否决,也反映了同样的治理动态。 目前卡尔达诺面临一个严峻考验:其治理体系已有能力否决包括核心机构在内的重大支出请求,但能否在市场下行期迅速行动以保全关键基础设施,同时避免重建其意在消除的中心化依赖,仍是一个难题。截至发稿时,ADA交易价格为0.1886美元。

bitcoinist1小时前

卡尔达诺创始人霍斯金森称“将短暂离开”:事情始末

bitcoinist1小时前

卡尔达诺(Cardano)要完了吗?查尔斯·霍斯金森警告“失败浪潮”将至——他自己的社区怒不可遏

卡尔达诺(Cardano)联合创始人查尔斯·霍斯金森近日发布视频警告,称2026年下半年该生态系统将出现项目失败潮、被迫整合及DeFi关闭。此番言论引发其社区强烈不满。此次预警的导火索是卡尔达诺核心数据分析平台TapTools于6月2日宣布将在两周内停止运营,原因是基础设施成本与开发支出难以为继,团队多名核心成员也已离职。 霍斯金森将此事视为生态系统深层压力的征兆,指出许多早期项目已不具备投资价值,并承认自己曾提议的国库资助指数计划未能落实。他随后在X平台上表示将“休息一下”,此言在当下时点引发更多猜测。 加密社区反应迅速且尖锐。Nansen首席执行官安德烈亚斯·斯瓦内维克等人批评霍斯金森过往对卡尔达诺的机构潜力与开发采用做出了不切实际的承诺,导致社区期望落空。数据显示,卡尔达诺总锁仓价值(TVL)仅约1.2385亿美元,排名第28位,远远落后于以太坊等公链。此外,2026年卡尔达诺峰会被取消,工程预算遭大幅削减,ADA价格也跌至五年多来最低点约0.20美元。 霍斯金森的言论让社区不得不面对一个尖锐问题:在其创始人近乎“末日预言”的描述下,卡尔达诺能否逆转颓势?目前,生态系统尚未给出明确答案。

bitcoinist5小时前

卡尔达诺(Cardano)要完了吗?查尔斯·霍斯金森警告“失败浪潮”将至——他自己的社区怒不可遏

bitcoinist5小时前

交易

现货
合约
活动图片