Shipping Records Exposed: A New Vulnerability in Bitcoin Wallet Security
A vulnerability in Bitcoin wallets has been discovered that doesn't involve hacking into the wallet itself, but rather exploiting the shipping records of hardware wallet purchases. According to Trezor, a company that produces secure Bitcoin storage devices, approximately 80,689 customers had their contact and delivery information compromised due to a breach by its shipping provider, ShipMonk.
The leaked information included names, addresses, and order details, which can be used to impersonate the wallet owner or trick them into revealing sensitive recovery words. This is particularly concerning because hardware wallets are designed to keep private keys separate from computers and other devices that could be compromised by malware.
Trezor claims that its systems and devices were unaffected by the breach, and no funds were stolen as a result. However, the company notes that the information exposed can still be used for phishing scams or identity theft.
The incident highlights the importance of protecting sensitive information beyond just the wallet itself. Wallet owners should be cautious when receiving unsolicited messages or requests for their recovery words, and ensure that they follow best practices for securing their identities and financial information.