Hardware Wallet Security Not Compromised as Surrounding Systems Exposed
Two recent incidents involving popular crypto hardware wallets D'CENT and Trezor have exposed a growing weakness in self-custody security. Both companies reported unauthorized transactions from users of their software-based App Wallets, but fortunately, none of the hardware wallet security was compromised.
The problem lies not with the devices themselves, but with the systems surrounding them. D'CENT's App Wallet allows users to import or store keys on a phone, and if a recovery phrase is entered into this software, it can extend risk beyond the original device where the wallet was created.
Trezor's incident began when an attacker exploited a flaw in its third-party marketing provider Brevo's SAML single-sign-on implementation. This allowed them to export 347,149 customer email contacts and use them to send phishing emails through legitimate customer infrastructure. The risk arose if a user entered their wallet backup into the malicious application.
While neither company has reported a compromise of its hardware-wallet security, both incidents highlight the importance of limiting retained customer data and vetting outside vendors. Wallet makers will increasingly have to show how they design companion software so that a compromise elsewhere in the stack doesn't provide another path to the keys their hardware was built to protect.
As D'CENT continues to investigate the cause and total scope of the transfers, it is advising users who meet its criteria to update the app before signing another transaction, create a wallet backed by a new recovery phrase, and transfer affected assets. The company is also working with exchanges, law enforcement, and blockchain investigators to trace and potentially freeze stolen assets.