Trezor says phishing, not SIM swap, compromised X account

cyptouser7 months agoCryptocurrencies News115
25cc9d4a>

SatoshiLabs, the company that designs and markets Trezor crypto hardware wallets, has issued a detailed explanation of an incident that led to the posting of fraudulent presale token announcements on its official X account.

The company said the security breach was caused by a phishing attack, not a SIM-swap attack, which it suspected at the time.

SatoshiLabs emphasized that it does not use a mobile device for two-factor authentication, instead opting f.

Despite these precautions, attackers made a series of unauthorized and misleading posts, including requests for users to send funds to an unidentified wallet address alongside harmful links, which sent users to a bogus token presale site.

Independent blockchain sleuth ZachXBT notified his 528,000 followers on X of Trezor’s suspected breach in a March 19 X post.

The official X account of hardware wallet manufacturer Trezor published a series of posts directing users to fraudulent presale token offerings.

Source: Trezor

SatoshiLabs disclosed that it detected unauthorized entry into its X account on March 19. It now suspects it to be a sophisticated and premeditated phishing attack planned by hackers over several weeks.

Once SatoshiLabs became aware of the breach, the deceptive posts were promptly identified and removed, limiting damage. The company said:

“We want to stress here that the security of all our products remains unaffected. This incident has in no way impacted or compromised the security of Trezor hardware wallets or any of our other products.”

Investigations indicate that starting on Feb. 29, the attackers posed as credible entities in the cryptosphere. They maintained a convincing social media presence and engaged in seemingly authentic discussions.

Related: HECO Chain exploiter anonymizes $145M of Ether on Tornado Cash in 8 days

Under the guise of a well-established X account with thousands of followers, the impersonator contacted SatoshiLabs’ public relations team, suggesting an interview with the CEO. Following this, a meeting was arranged, during which the impersonator shared a malicious link disguised as a Calendly calendar invitation.

A team member was prompted for their X login credentials by clicking the calendar link, raising suspicion. However, the meeting was rescheduled. In the next session — pretending to be facing technical issues — the attacker succeeded in linking their Calendly to SatoshiLabs’ X account.

Trezor suffered a security breach in January that exposed the contact information of nearly 66,000 users. According to the firm’s website, the wallet maker has sold over two million hardware wallets since it launched in 2012.

Magazine: $3.4B of Bitcoin in a popcorn tin — The Silk Road hacker’s story

The content on this website comes from the Internet. Due to the inconvenience of proofreading the authenticity and accuracy of the copyright or content of some content, it may be temporarily impossible to confirm the authenticity and accuracy of the copyright or content. For copyright issues or other issues caused by this, please Call or email this site. It will be deleted or changed immediately after verification.

related articles

EOS Network approves new tokenomics, promises ‘new era’

EOS Network approves new tokenomics, promises ‘new era’

55966e89˃The EOS ecosystem has reached a consensus to approve a new tokenomics model, promising a “n...

5 crazy April Fools pranks that Crypto X almost fell for

5 crazy April Fools pranks that Crypto X almost fell for

25cc9d4a˃From Vitalik Buterin touting “degen communism” to a white paper from the Solana CEO for a t...

Bitcoin Bollinger Bands hit level that saw BTC price squeeze past $50K

Bitcoin Bollinger Bands hit level that saw BTC price squeeze past $50K

1205f261˃Bitcoin (BTC) stuck near $66,000 on April 23 as waiting sellers kept BTC price action firml...

House digital assets subcommittee hears testimony on role of crypto in crime and illicit finance

The U.S. House Subcommittee on Digital Assets, Financial Technology, and Inclusion heard testimony t...

Gemini confirms it withdrew $282M from Genesis to boost liquidity reserves in 2022

Gemini has confirmed it withdrew $282 million of its Earn users funds from the bankrupt crypto lende...

Crypto platform Yield App shuts down citing FTX losses

Crypto platform Yield App shuts down citing FTX losses

55966e89˃Yield App, a Seychelles-incorporated crypto investment platform, announced on June 28 that...