Hardware Wallet Users Vulnerable to Phishing Attacks After Data Breaches
The recent data breaches at Trezor and SafePal hardware wallet manufacturers have exposed over 53,000 customers' personal information, including names, email addresses, phone numbers, and physical shipping addresses. However, the private keys and seed phrases remain secure.
This incident highlights the importance of personal data protection and physical security in cryptocurrency storage. The risk of targeted phishing attacks is now higher, as attackers can use this verified information to construct high-fidelity social engineering campaigns. These campaigns may request verification of the seed phrase under the pretense of a firmware update or direct the user to a cloned website to harvest credentials.
The exposure of phone numbers adds an additional risk layer, enabling SMS phishing (smishing) and phone call spoofing attacks. SIM swapping is also possible, allowing attackers to take control of the telephone line and intercept two-factor authentication codes based on SMS. This bypasses traditional multi-factor authentication.