Search This Blog

Powered by Blogger.

Blog Archive

Labels

Footer About

Footer About

Labels

Showing posts with label Trezor. Show all posts

Trezor Data Breach Rises to 67,000 US Customers


Hardware cryptocurrency wallet organization Trezor has disclosed that additional 67,000 customers in the US have been impacted by a data breach consisting of its shipping provider, ShipMonk. 

The recent news has notably increased the number of consumers potentially exposed in the incident.  “We're deeply saddened to share the news that the recent data breach affects more customers than originally thought,” Trezor said on X. 

As per Trezor, the additional 67000 customers placed orders from November 2019 to August 2021. 

What is leaked?

The leaked data consists of customers' email, phone numbers, names, addresses, order numbers, and shipping addresses. According to Trezor, the data was stored by ShipMonk even though Trezor had earlier received assurance that previous consumer data had been erased. 

“Throughout our entire relationship with ShipMonk, we repeatedly requested and received written assurance confirming the deletion of the data, in line with our contract, data policy, and past communications. We are very disappointed that, despite receiving this confirmation, the data was not deleted in their systems,” Trezor said.

According to experts, the breach is not impacting Trezor’s own systems. 

Who are impacted?

Trezor said its hardware wallets are safe and there are no signs that customers’ recovery seed phrases or private keys were breached in the leak. 

As per Trezor, “All affected customers have been emailed directly. If you didn’t receive an email, then you are not affected.”

Potential impact

But Trezor and cybersecurity experts are worried that the stolen data could be exploited for social engineering and targeted phishing attacks. Threat actors could misuse customers’ details regarding their Trezor purchases to create scam phone calls or fraud messages.

This can be a serious problem for cryptocurrency users. A threat actor could mimic a company employee if they know someone owns a Trezor wallet and ask the target to verify their wallet or account. 

User advisory

If successful, the attacker could steal the target’s recovery seed phrase, which can allow access to cryptocurrency funds. “Trezor systems were not compromised, and your device is secure. But please be alert for fake emails, phone calls, fraudulent letters, and potential risks to physical security,” the company added. 

The announcement comes after the August incident when 13,689 customers had been impacted by the same shipping-provider. At the time, Trezor estimated around 14,000 customers to have been affected by the breach. The recent disclosure of 67,000 suggests the scope of the incident was larger than expected.

Trezor Data Breach Exposes Personal Information of Nearly 14,000 Customers

 

Hardware cryptocurrency wallet maker Trezor has disclosed a data breach involving the personal information of nearly 14,000 customers, after an unauthorized party gained access to data held by its third-party fulfillment provider, ShipMonk.

Trezor said its own infrastructure was not compromised and that the incident was discovered after the company was informed of the attack on August 10. The affected customers are located in the US, UK, Sweden, Colombia, Brazil, Italy and Portugal and placed orders between May 10 and August 8.

According to Trezor, the breach exposed the names, phone numbers, email addresses and shipping addresses of 11,742 customers. Information belonging to another 1,947 customers included their names, cities and email addresses. The data had been provided to ShipMonk solely to facilitate order fulfillment and delivery.

“We’re extremely sorry to inform our community that customer personal information, including full names, phone numbers, email addresses, and shipping addresses, has been accessed by an unauthorized actor during this breach,” Trezor said in its security notice.

The company attributed the limited scope of the exposure to its 90-day data retention policy, which it said is also followed by its fulfillment partners. However, Trezor warned that older orders may have been accessible for some of the customers whose information was partially exposed.

Trezor stressed that the incident did not affect its internal systems or the security of its hardware wallets. “To be clear, our systems were not compromised, and your Trezor device is secure, but the affected customers might be targeted by more sophisticated phishing attempts,” the company said.

All customers believed to be affected have been contacted directly by email. Trezor urged them to remain cautious of unexpected messages, particularly those asking for personal details, cryptocurrency information or immediate action.

The company is working with ShipMonk to establish when the compromise occurred and determine the complete extent of the incident.

Reports indicate that ShipMonk informed customers that the attackers gained access to its systems by exploiting a vulnerability in Metabase, a data analytics platform. The incident may be connected to a recently patched SQL injection zero-day affecting Metabase.

The cybercrime group ShinyHunters has also claimed responsibility for an attack on Metabase and subsequently published data it alleged was stolen from the analytics provider. However, the connection between that incident and the ShipMonk breach has not been independently established.

ShipMonk has not publicly confirmed the breach. It also remains unclear whether other organizations or individuals were affected, how much information may have been accessed, and who was ultimately responsible for the attack.

Trezor Wallet: Not So Hack-Safe After All!









The hackers have found another way to penetrate the safety walls of the seemingly “quite safe” Trezor Wallet.


One of the inquisitive crypto-mining fans took to twitter, to shout out that the device which goes by the name of Trezor wallet has a vulnerability which lays bare  "un-password-protected" users.


This is not the first time such an attack has been possible on devices of the aforementioned kind and the researchers deem it as inevitable, given the poor fabrication of the devices.


At the Chaos Communication Congress, the theme was solidly elucidated and discussed upon, by specialists who talked about the hack-ability of crypt0-wallets.


The Congress spread across the different kinds of vulnerabilities, hardware, software and firmware could be affected by.


The gathered specialists expounded about recurring and systematic problems in wallets.


The team also worked upon creating a library of malicious attacks related with harvesting of funds from the hardware wallet.


The vulnerabilities these wallets possess, the ways to move around them and the available courses of action were discussed at the congress at length.


The team demonstrated how breaking the boot-loader protection and breaking web interfaces which are used to communicate with the wallets, is done.


Some physical attacks such as “Glitching”(an attempt at bypassing security of the micro-controllers of the wallet) were also a part of the CCC team’s drill.


The vulnerabilities uncovered by the team, have detailed implications which could only be solved via a firmware update or even a new hardware revision.


There is hope as to companies deliberating on the severity of the situation and that they will put forth some improvements.


With an extreme rise in the trend if hardware wallets, there has also been an extreme rise in the users, given these devices hoard a consequent number of crypto-currency.


There exist crypto-traders who work essentially and daily over and on these famous wallets.


Thousands and Millions of dollars’ worth crypto-currency is stored within the “walls” of these hardware wallets, rendering the reason behind all these attacks on them, apparent.


As to what the recently found attack did? It majorly concerned and focused upon breaking the interfaces that aid the communication with the wallet.

  
The Trezor wallet was attached to various devices which included a socket with an FPGA. Then supposedly a code was run to give the hackers access to the seed and pin.
But the hack would only go through if the wallet wasn’t password protected.


The engineer who is in charge of Trezor, Pavol Rusnak, took to twitter to let the public know that they weren’t previously privy to the situation.


But, now that they are, by the end of January a new firmware update will see its way through to the wallet.


He also cited that the issue is currently being investigated and that it soon is expected to be patched.