Security· ★★★· bearish·

D’CENT and Trezor: wallet-related leaks create seed-phrase risk

  • D’CENT: risk for wallets with an imported seed phrase and transaction signing on versions below 8.1.0
  • Trezor: leak of 347,149 email contacts via Brevo, with about 2,500 recipients visiting a phishing domain
  • Brevo: attack via a SAML SSO vulnerability affected 138 accounts, with contacts exported from 43
  • Both companies say the hardware wallets themselves were not hacked
Why it matters: Risk is shifting from device chips to vendor software and databases: a leaked seed phrase or phishing wipes out the protection of a hardware wallet.
Source: CryptoSlate