• About
  • Privacy Poilicy
  • Disclaimer
  • Contact
CoinInsight
  • Home
  • Bitcoin
  • Ethereum
  • Regulation
  • Market
  • Blockchain
  • Ripple
  • Future of Crypto
  • Crypto Mining
No Result
View All Result
  • Home
  • Bitcoin
  • Ethereum
  • Regulation
  • Market
  • Blockchain
  • Ripple
  • Future of Crypto
  • Crypto Mining
No Result
View All Result
CoinInsight
No Result
View All Result
Home Future of Crypto

Crypto hardware wallet makers have a new security problem

Coininsight by Coininsight
September 18, 2026
in Future of Crypto
0
189
SHARES
1.5k
VIEWS
Share on FacebookShare on Twitter

Related articles

Lagarde Reportedly Blocked Binance’s Greek MiCA License Bid

September 19, 2026

Crypto.com Gets Green Light to Bring Single-Stock Futures to the US

September 17, 2026


Two wallet incidents this week exposed a growing weakness in crypto self-custody: the systems surrounding hardware devices.

D’CENT, a popular hardware wallet in South Korea, said it is investigating unauthorized transfers from some users of its software-based App Wallet, while Trezor, another crypto hardware firm, disclosed that attackers exported 347,149 customer email contacts after breaching third-party marketing provider Brevo.

Neither company has reported a compromise of its hardware-wallet security.

Yet both incidents created routes to the same prize: the recovery phrase that can reconstruct a wallet and control its assets.

Crypto hardware wallet makers have a new security problem Crypto hardware wallet makers have a new security problem

D’CENT phrase reuse pulls hardware assets into software risk

D’CENT’s investigation shows how moving a recovery phrase into software can extend risk beyond the device where the wallet was originally created.

The company first received reports of unauthorized transfers on Sept. 16 and found that most affected users were operating its App Wallet, which stores or imports keys on a phone. D’CENT has not confirmed a compromise affecting its hardware products and continues to investigate the cause and total scope of the transfers.

Its current criteria focus on wallets whose recovery phrases were entered into the App Wallet and that had transaction-signing history on versions earlier than 8.1.0, released Nov. 5, 2025. The potential exposure spans Bitcoin, Ethereum, XRP Ledger, Tron, and other EVM-compatible networks.

That creates a potential crossover for hardware users. A recovery phrase generated on a D’CENT device can reconstruct the same private keys elsewhere if the user later imports those words into the software wallet. D’CENT said connecting a hardware device to its app normally does not transfer the recovery phrase onto the phone; manually importing the phrase into App Wallet does.

The company is advising users who meet its criteria to update the app before signing another transaction, create a wallet backed by a new recovery phrase, and transfer affected assets rather than restoring the old phrase onto another device.

D’CENT is also working with exchanges, law enforcement and blockchain investigators to trace and potentially freeze stolen assets.

Trezor breach turns customer data into an attack surface

Trezor’s incident began further from the wallet itself, showing how information about who owns a device can become useful infrastructure for attackers.

The Catalyst

What’s moving crypto. Why it matters.

Get CryptoSlate’s essential stories and what to watch next.

Published on Substack

Seven days a week. Unsubscribe anytime.

Whoops, looks like there was a problem. Please try again.

Check your inbox.

Your signup request was sent. If confirmation is required, follow the email from Substack.

Look in spam or promotions if you don’t see it.

Brevo said an attacker exploited a flaw in its SAML single-sign-on implementation to reach 138 customer accounts. Contacts were exported from 43 accounts, while six were used to send phishing emails through legitimate customer infrastructure. The messages therefore passed normal email-authentication checks and appeared to originate from trusted systems.

For Trezor, the breach exposed 347,149 marketing email contacts. Attackers sent a message claiming a critical hardware vulnerability and requiring customers to download an application that then requested their wallet backup. About 2,500 recipients reached the malicious domain before Trezor disabled it.

Related Reading

Attackers exploit fake STM32 vulnerability alert to target Trezor and BitBox holders

Trezor said clicking the link alone did not expose funds. However, the risk arose if a user entered the backup into the malicious application, allowing an attacker to recreate the wallet elsewhere.

The exported email list creates a longer-lived problem even after the first phishing domain has disappeared. Verified contact details for hardware-wallet users can be reused in follow-up campaigns tailored around future security alerts, software updates, or support requests.

Trezor had already confronted a related exposure in August when a shipping-provider incident disclosed customer identity and order information. The company said that breach exposed phone numbers and shipping addresses while leaving its wallets unaffected.

The two events show how vendors outside a hardware maker’s direct infrastructure can supply attackers with information needed to identify likely crypto holders and build more convincing approaches.

Wallet makers face a wider security burden

The incidents are likely to increase pressure on wallet companies to treat customer databases and software workflows as part of the same security program as their devices.

Trezor said it has suspended its Brevo account and is reviewing vendor relationships and security requirements following the breach. Brevo closed the SSO route used by the attacker, reset active sessions, and said it was deploying a permanent fix that restricts authentication to the organization that owns each SSO configuration.

D’CENT, meanwhile, said it is adding safeguards and pre-release verification procedures while its investigation continues. Its immediate challenge is determining the full set of affected addresses and whether assets already moved can be recovered through exchanges or law enforcement.

Both companies still depend on users keeping recovery phrases offline. Once those words are entered into compromised software or surrendered through phishing, the attacker no longer needs to defeat the hardware device.

That shifts part of the competitive burden for wallet makers beyond secure chips and signing architecture.

Companies selling self-custody products will increasingly have to show how they limit retained customer data, vet outside vendors, and design companion software so a compromise elsewhere in the stack doesn’t provide another path to the keys their hardware was built to protect.

Share76Tweet47

Related Posts

Lagarde Reportedly Blocked Binance’s Greek MiCA License Bid

by Coininsight
September 19, 2026
0

European Central Bank President Christine Lagarde reportedly stepped in to block Binance from securing an EU wide crypto license via...

Crypto.com Gets Green Light to Bring Single-Stock Futures to the US

by Coininsight
September 17, 2026
0

Crypto.com is targeting US traders with single-stock futures through OG.com. Crypto.com is moving closer to launching single-stock futures in...

TREAD is available for trading!

by Coininsight
September 17, 2026
0

We’re thrilled to announce that TREAD is available for trading on Kraken! Funding and trading TREAD trading is live as...

Payward Wants to Put US-Regulated Perpetual Futures on Hyperliquid

by Coininsight
September 16, 2026
0

Payward plans to bring US-regulated perpetual futures to Hyperliquid’s on-chain order book. The markets would use Hyperliquid’s infrastructure, but access,...

Ripple Puts XRP on Louisville Courts, Expanding Its $5M College Sports Push

by Coininsight
September 16, 2026
0

Key Takeaways:Ripple extends Louisville Basketball on the XRP’s sports sponsorship campaign.XRP logos will be prominently featured at home games at...

Load More
  • Trending
  • Comments
  • Latest
What’s Actually Going On With Ripple’s Blockchain?

What’s Actually Going On With Ripple’s Blockchain?

January 12, 2026
MetaMask Launches An NFT Reward Program – Right here’s Extra Data..

MetaMask Launches An NFT Reward Program – Right here’s Extra Data..

July 24, 2025
Finest Bitaxe Gamma 601 Overclock Settings & Tuning Information

Finest Bitaxe Gamma 601 Overclock Settings & Tuning Information

November 26, 2025
Easy methods to Host a Storj Node – Setup, Earnings & Experiences

Easy methods to Host a Storj Node – Setup, Earnings & Experiences

March 11, 2025
Kuwait bans Bitcoin mining over power issues and authorized violations

Kuwait bans Bitcoin mining over power issues and authorized violations

2
The Ethereum Basis’s Imaginative and prescient | Ethereum Basis Weblog

The Ethereum Basis’s Imaginative and prescient | Ethereum Basis Weblog

2
Unchained Launches Multi-Million Greenback Bitcoin Legacy Mission

Unchained Launches Multi-Million Greenback Bitcoin Legacy Mission

1
Earnings Preview: Microsoft anticipated to report larger Q3 income, revenue

Earnings Preview: Microsoft anticipated to report larger Q3 income, revenue

1

European Central Bank President Blocked Binance’s EU Entry

September 19, 2026

eth2 quick update no. 21

September 19, 2026

Lagarde Reportedly Blocked Binance’s Greek MiCA License Bid

September 19, 2026

The Cage of Grandfathering: Why FCC Protection Won’t Save Foreign-Produced AI Robotics

September 18, 2026

CoinInight

Welcome to CoinInsight.co.uk – your trusted source for all things cryptocurrency! We are passionate about educating and informing our audience on the rapidly evolving world of digital assets, blockchain technology, and the future of finance.

Categories

  • Bitcoin
  • Blockchain
  • Crypto Mining
  • Ethereum
  • Future of Crypto
  • Market
  • Regulation
  • Ripple

Recent News

European Central Bank President Blocked Binance’s EU Entry

September 19, 2026

eth2 quick update no. 21

September 19, 2026
  • About
  • Privacy Poilicy
  • Disclaimer
  • Contact

© 2025- https://coininsight.co.uk/ - All Rights Reserved

No Result
View All Result
  • Home
  • Bitcoin
  • Ethereum
  • Regulation
  • Market
  • Blockchain
  • Ripple
  • Future of Crypto
  • Crypto Mining

© 2025- https://coininsight.co.uk/ - All Rights Reserved

Social Media Auto Publish Powered By : XYZScripts.com
Verified by MonsterInsights