Skip to main content

Trezor warns of phishing attack targeting users



Trezor has warned users of its hardware wallet about a phishing scam it said was related to an earlier hack on one of its competitors. The company said the attackers claim a user's wallet has been disabled, before redirecting to a clone site to steal their credentials.

In a blog post, Trezor revealed that the attackers have been sending its users emails claiming they need to pass verification due to new KYC regulations. It then provided a website that's a replica of wallet.trezor.io on which the users can supposedly verify their identity. This site requests the users to key in their recovery seed, giving the attackers full control of the wallet.

Trezor reminded its users that they "will not be asked to enter their seed anywhere other than on their Trezor device." It also assured its users that all their funds are safe and that no Trezor customer data has been leaked.

"We continue to operate under a policy where we anonymize all customer data from e-commerce within 90 days, once it is no longer needed to complete the order, and will even remove customer data manually if requested before that," the firm stated.

Trezor believes that the recent wave of phishing attacks was a result of a hack on its hardware wallet competitor Ledger. The French company was hacked in late June, with the attackers accessing one million emails. They also accessed additional details such as postal addresses, first and last names and phone numbers for close 9,500 of the users.

Trezor believes that this is the data the attackers in the latest phishing attack are relying on.

"The timing and scope of this phishing scheme suggests it is a second wave of attacks resulting from a breach of our competitor's e-commerce database. Malicious actors who acquired the data from that attack are blindly targeting Ledger customers whom they presume may also own a Trezor wallet."

Trezor advised its users against ever digitizing their recovery seed or sharing them. They should also ensure they perform every important action using their hardware wallets.

This is not the first phishing campaign that has relied on data from the July Ledger hack. In October, thousands of Ledger users were targeted by a phishing attack that many described as "really legit-looking." The attackers told the targets that Ledger had found several of its servers to be infected with malware.

One user described the attack on Reddit, "Wow this looked really legit, so much so I used Contact Us form to ask Ledger if it was real. I am normally pretty good at sniffing things like this out – this was by far the most convincing attempt I have ever seen."

See also: CoinGeek Live presentation, Custody Changes Everything: How BSV Opens a New World for Digital Asset Custodians

Comments

Popular posts from this blog

What is TogaCoin?

TogaCoin is here to stay for a long time because this token sale is not only about cryptocurrencies but also about other important areas of the world economy. Yes, you heard it right and we will be telling you more interesting things about this token sale right away. Unique Selling Points You will be paid during the token sale. Yes, it is true and you should think about it right away. In fact, you could end up earning up to 20% of the invested money per month. Really? Yes, it is true and you should be happy with it. Explainer video Features These guys have a lot of experience in the world of IT and they will shine with this token sale. TogaCoin's staff will work on the important field of cryptocurrency mining and even in data management. These are amazing fields that could generate a lot of money down the road. Technical Analysis Well, TogaCoin will work hard to make money via these activities: -0Electricity is a very important part of the world econom...

The Bitquence Liquidity Network

CryptoCurrency is gaining popularity, however with Bitcoin very user-unfriendly mass adoption is not coming. The Bitquence Platform is aiming to replace Bitcoin with it's many disadvantages with something better. A currency for the people. More and better usability, A wallet which is universal and support several coins, like Bitcoin but also Dash and Ethereum. Please read along to get the latest information about this project which can grow very large. Collection of abnormal pockets programs, With automated sources that oversee a large number of wallets for each and every of your financial paperwork making it exhausting to do. International Cryptocurrencies lately stay on experiencing an especially noteworthy increment, impulsively reaching colossal valuations. The have an effect on at the present economic system modified the psyches of people to take after enhancements within the time of Cryptocurrency. Virtual kinds of cash and blockchain innovation are lat...

GrantShares DAO launching to support ecosystem growth and grassroots initiatives

The GrantShares DAO is launching on Neo N3 to distribute funding to grassroots developers and ecosystem beneficial projects. The DAO will manage an initial treasury funded by the Neo Foundation. As the first DAO to launch on Neo N3, GrantShares is designed to provide financial support to smaller initiatives that do not currently fit the scope of Neo's existing grant programs. Voting members of the organization include COZ, AxLabs, Red4Sec, NGD Enterprise, NeoResearch, NEXT, Neo SPCC, Neo Foundation, Neo Global Development, and Neo News Today. Anyone is encouraged to submit a proposal for the members of the DAO to discuss and vote. The initial funding limit for GrantShares is $50,000 per proposal, and can be used to fund local events, dApps, developer tools, education initiatives, and more. Projects seeking larger amounts should apply for grants through one of Neo's Eco Support tracks. The DAO's smart contracts are developed and maintained by AxLabs and have already been dep...