Skip to main content

Trezor warns of phishing attack targeting users



Trezor has warned users of its hardware wallet about a phishing scam it said was related to an earlier hack on one of its competitors. The company said the attackers claim a user's wallet has been disabled, before redirecting to a clone site to steal their credentials.

In a blog post, Trezor revealed that the attackers have been sending its users emails claiming they need to pass verification due to new KYC regulations. It then provided a website that's a replica of wallet.trezor.io on which the users can supposedly verify their identity. This site requests the users to key in their recovery seed, giving the attackers full control of the wallet.

Trezor reminded its users that they "will not be asked to enter their seed anywhere other than on their Trezor device." It also assured its users that all their funds are safe and that no Trezor customer data has been leaked.

"We continue to operate under a policy where we anonymize all customer data from e-commerce within 90 days, once it is no longer needed to complete the order, and will even remove customer data manually if requested before that," the firm stated.

Trezor believes that the recent wave of phishing attacks was a result of a hack on its hardware wallet competitor Ledger. The French company was hacked in late June, with the attackers accessing one million emails. They also accessed additional details such as postal addresses, first and last names and phone numbers for close 9,500 of the users.

Trezor believes that this is the data the attackers in the latest phishing attack are relying on.

"The timing and scope of this phishing scheme suggests it is a second wave of attacks resulting from a breach of our competitor's e-commerce database. Malicious actors who acquired the data from that attack are blindly targeting Ledger customers whom they presume may also own a Trezor wallet."

Trezor advised its users against ever digitizing their recovery seed or sharing them. They should also ensure they perform every important action using their hardware wallets.

This is not the first phishing campaign that has relied on data from the July Ledger hack. In October, thousands of Ledger users were targeted by a phishing attack that many described as "really legit-looking." The attackers told the targets that Ledger had found several of its servers to be infected with malware.

One user described the attack on Reddit, "Wow this looked really legit, so much so I used Contact Us form to ask Ledger if it was real. I am normally pretty good at sniffing things like this out – this was by far the most convincing attempt I have ever seen."

See also: CoinGeek Live presentation, Custody Changes Everything: How BSV Opens a New World for Digital Asset Custodians

Comments

Popular posts from this blog

What is iDice?

iDice is a dice betting Dapp fueled by the use of the Ethereum organize. eg. iDice lets in players do several things and having such an innovative new token on the ETHEREUM Platform, we had to write an article about this new project. Guess on the space by the use of keeping up iDice tokens and best of all 100% of all benefit iDice acquires is dispersed among token holders, related to the amount of tokens they dangle. iDice amusement code is decentralized and changeless. Such gigantic building fees highlight a rising requirement for experienced, fair and cast Dapps. iDice iDice is an control which gives a provably affordable and simple, virtual Ethereum dice betting Dapp. The house edge will be set intensely and token holders have an atypical esteem that is dependably equiva- loaned to the house edge. iDice has a fully simple provide code accessible at etherscan.io. The payout of recreations is many times speedy. Provably Fair iDice uses open provide blockchain...

DENT: THE World First Tokenizing Portable Information Trade

You may be confused on all the exciting Ethereum projects, but therefore i make sure to follow allof them and choose the best for you. If you want to read about a more interesting project, then DENT is the way to go. I will be able to advice on a few tokens that can be bought out there which clearly we likewise might occu : Estimated token incentive on ETH presented within the token deal: 152,000 ETH (Relying on sorts via crowdsale) 100 Billion (100,000,000,000) the amount of DENT Tokens made, of which 70% is bought on token deal, a minimum of 35% can be stored for customers with littler spending plans. For the ones of you who're eager about ico smartcontract prolong that we regularly listen in non-obligatory cryptographic cash or altcoin without a doubt no longer outdoor to the workings of undertakings like this. Evaluated swapping scale: 1 ETH = 400,000 DENT 30% will keep on DENT Wi-fi for DENT shopper motivating forces and compensations Bills may well be made via ETH...

Fake Libra scams pose new challenge for Facebook

Almost a year after Facebook's Libra was first announced, the outlook for the stablecoin looks starkly different. Once hailed as a game-changer for digital currency, the project has been beset by delays and regulatory difficulties. Now, fake Libra scams are presenting an increasingly pressing new challenge for Libra and Facebook, with a proliferation of websites claiming to offer investment schemes denominated in fake Libra tokens. Dante Disparte, Deputy Chairman and Head of Policy and Communications for The Libra Association, said the organization was now constantly working to suppress fake Libra scams: "As we become aware of these sites, we work diligently to address them. We respond to inquiries concerning the validity of these pages, indicating that the only official website is Libra.org." "We are still in the early stages of this project and work to address issues like these as they arise," Disparte told Finance Magnates, urging people to report the scams. ...