Hardware Wallet Security Breaches Expose Weakness in Crypto Self-Custody
Two recent incidents involving popular hardware wallets D'CENT and Trezor have exposed a growing weakness in crypto self-custody: the systems surrounding these devices.
D'CENT, a hardware wallet in South Korea, is investigating unauthorized transfers from some users of its software-based App Wallet. The company has not confirmed a compromise affecting its hardware products but found that most affected users were operating its App Wallet, which stores or imports keys on a phone.
According to D'CENT's investigation, the recovery phrase generated on a D'CENT device can reconstruct the same private keys elsewhere if the user later imports those words into the software wallet. The company is advising users who meet its criteria to update the app before signing another transaction and transfer affected assets rather than restoring the old phrase onto another device.
Trezor's incident began with a breach of third-party marketing provider Brevo, where an attacker exploited a flaw in SAML single-sign-on implementation to reach 138 customer accounts. The breach exposed 347,149 marketing email contacts, which were used to send phishing emails to customers, aiming to trick them into entering their wallet backup.
Both incidents show how vendors outside a hardware maker's direct infrastructure can supply attackers with information needed to identify likely crypto holders and build more convincing approaches.