Crypto wallets are hacked by sending messages.

Words
433
Reading
2 min
Listen
Play
1d

A new cyber attack has spread panic in the crypto world. Fake emails are being sent to popular hardware wallet users. Millions of users are now at risk. The question is how it all happened. Trezor, the manufacturer of hardware wallets used to keep crypto assets safe, said that about 347,000 of their customers have received phishing emails.

Scr

The incident came to light recently and quickly gained importance around the world. Behind this incident is the hack of a third-party marketing platform Brevo. Trezor used this service to send their email newsletter. Hackers exploited a vulnerability in the single sign-on system on the platform to gain unauthorized access to multiple accounts. Brevo said that the attacker first created his own account and enabled SSO there.

Then, legitimate users were invited to that set up. As a result, they could log in to the system normally using the user's identity. The problem is even bigger because this access was supposed to be limited to a specific organization. But due to a technical error, the attacker was able to access the data of all organizations associated with the users.

Scr

This put the information of many organizations at risk at the same time. According to Brevo, at least six accounts were used to send phishing emails. In addition, contact information from four accounts was collected. This data included the email addresses of a large number of Trezor customers. Trezor said that the subject of the email sent to customers was an urgent security alert. There, users were asked to click on a link.

The message was crafted in such a way that it looked like a real warning and was easily credible. By clicking on the link, users entered a fake website. There, they were asked to provide a wallet backup or seed phrase. Providing such information could directly put the user's assets in the hands of hackers. The company took quick action immediately after the incident.

According to their estimates, about 2500 users clicked on that link. However, the fake website was shut down within just twenty minutes. As a result, it was possible to somewhat control the large damage. However, it is still unclear how many users suffered financial losses. No details were given about the total amount of damage.

As a result, many users remain concerned and new questions about security have been raised. The same incident has affected some other organizations. Switzerland-based hardware wallet maker BitBox and crypto tax service platform CoinTracking are also believed to have been affected, but they have yet to officially disclose details.

Crypto wallets are hacked by sending messages. | Ecency