home.social

#trezor — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #trezor, aggregated by home.social.

fetched live
  1. CRYPTO · Trezor's shipping partner breach exposes 14,000 buyers

    A breach at Trezor's shipping partner leaked the names, emails, and addresses of nearly 14,000 crypto wallet buyers.

    Read the rest at: thedailyfathom.com/crypto/2026

    #Crypto #Trezor #ShipMonk #TheDailyFathom

  2. 📢⚠️ A breach at Trezor shipping provider ShipMonk compromised personal and delivery data belonging to 13,689 customers in seven countries. Trezor says its systems and hardware wallets remain secure.

    Listen/Read: hackread.com/shipmonk-breach-t

    #CyberSecurity #DataBreach #Trezor #ShipMonk #Crypto

  3. Oh, le retour de la campagne de 🎣 #phishing #trezor

    Il faut quand même lui reconnaître une certaine inventivité : dans cette énième itération, la mise en scène est particulièrement théâtrale 🎭

    Acte I : le petit mail #Reddit bien amical annonçant une mise à jour du firmware.

    Acte II : un faux r/TREZOR, avec publication, commentaires et modération — parce que le décor, c’est important.

    Acte III : la fausse application web qui propose de « connecter et déverrouiller » le Trezor… et de vider le wallet.

    Chaîne :

    hxxps[://]trezorsubreddit[.]com/?view=reddit
    hxxps[://]websuitetrezor[.]com/?acc

    Rideau. Et probablement disparition des cryptos. 🎭

    #CyberVeille

  4. I’m actually getting phone calls from my #phishing friends now too. The first was a pretty obvious scammer trying to convince me he was from #Trezor support. This was an American sounding guy from an LA number. My mistake was not saying “what’s a Trezor?” and hanging up. Instead I laughed and said there’s no way they would call. So now they know I knew what Trezor is and that suggests I have one full of bitcoin (I don’t).

  5. First off, they’re emailing me constantly with phishing attempts (like the image supposedly showing a #Trezor update on Medium) that are decently constructed but not really convincing. Just look at the sender address and the whole scam becomes clear.

  6. Tiens, itération intéressante de la campagne de vol de wallets #Trezor : les attaquants détournent maintenant le canal Medium pour crédibiliser la démarche, en sachant que la société communique effectivement via ce support.
    Faux mail « Trezor published a new story » (article « After the incident: what's confirmed, what isn't, and what to do now »), envoyé via SendGrid.
    Le mail arrive depuis noreply@brandyourself[.]com : très probablement le compte SendGrid de cette boîte de e-réputation qui est abusé comme relais.

    👀
    ⬇️
    lookyloo.circl.lu/tree/71bff42

    La chaîne de redirection :
    email.brandyourself (SendGrid /ls/click) → redirect-region-5[.]com → breach-mediumtrezor[.]com (faux Medium)

    On retombe sur la page classique des autres campagnes : fausse mise à jour de Trezor Suite, avec un domaine lookalike ad-hoc. (→ trezorsuite-update[.]com)

    #cyberVeille #phishing #infosec #crypto

  7. [Перевод] Как я взломал аппаратный криптокошелёк и вернул два миллиона долларов

    Представьте, что у вас есть два миллиона долларов, хранящихся на куске кремния размером с почтовую марку, а пароль от них вы забыли. Существует множество разных чипов подобного типа. Аппаратные кошельки предназначены для защиты восстанавливающих доступ строк в мире криптовалют. Однако многие люди забывают свои пароли, а если забыть пароль, то вы не сможете получить доступ к информации на чипе и потеряете деньги. О такой проблеме и пойдёт речь в нашей статье. Однажды со мной связались неизвестные мне люди. У них был аппаратный кошелёк Trezor, на котором хранилась пара миллионов долларов. Они спросили меня, смогу ли я взломать кошелёк и получить доступ к информации, чтобы они могли доказать, что деньги принадлежат им. Меня зовут Джо Гранд, я хакер оборудования. Взлом подобного продукта — потрясающая задача, похожая на решение головоломки, и у нас есть только один шанс сделать всё правильно. Хакинг не похож на то, что показывают в фильмах. Нет никаких графических эффектов, движущихся по экрану, ничто не происходит за доли секунды. Это американские горки, решение головоломок, принуждение оборудования делать то, чего оно не ожидает. Первым делом мы подписали договор об отказе от претензий на случай, если что-то пойдёт не так. А потом я двенадцать недель работал над этим проектом, пытаясь взломать защиту надёжным образом, чтобы при этом не удалилось содержимое устройства.

    habr.com/ru/companies/ruvds/ar

    #trezor #аппаратные_кошельки #криптовалюта #ruvds_переводы

  8. Nowa kampania phishingowa wycelowana w posiadaczy sprzętowych portfeli Trezor i Ledger

    Myli się ten, kto uważa, że pozostawanie off-line może zagwarantować bezpieczeństwo. Na pewno nie jest tak w świecie kryptowalut. Ostatnia kampania przypuszczona na użytkowników portfeli sprzętowych Trezor i Ledger bezlitośnie zadaje kłam temu twierdzeniu. TLDR: Sprzętowe portfele kryptowalutowe to fizyczne urządzenia zaprojektowane do bezpiecznego przechowywania prywatnych kluczy i do bezpiecznego...

    #WBiegu #Kradzież #Kryptowaluty #Ledger #Phishing #Portfele #Trezor

    sekurak.pl/nowa-kampania-phish

  9. Joe Grand recovering Trezor cold wallets, and the stories behind how the PINs and seed phrases were lost 🙂

    youtu.be/MhJoJRqJ0Wc

    #CryptoCurrency #Trezor #DataRecovery #JoeGrand

  10. 📬 Hackers Are Literally Mailing You Scam Letters 📬

    Threat actors are sending physical letters through postal mail pretending to be from Trezor and Ledger, manufacturers of cryptocurrency hardware wallets. The letters use official-looking branding and urgent language to trick recipients into revealing their wallet recovery phrases on fake websites. The scam represents a sophisticated blend of physical and digital social engineering.

    Sources:
    bleepingcomputer.com/news/secu
    cryptotimes.io/2026/02/16/ledg
    crypto.news/crypto-hackers-tar
    phemex.com/news/article/scamme

    #Cryptocurrency #Trezor #Ledger #PhishingScam #HardwareWallet
    ----------

    🤖 Trusted AI Tool Weaponized to Hack Macs 🤖

    Threat actors are abusing Claude AI's Artifacts feature and Google Ads in ClickFix campaigns that deliver infostealer malware to macOS users. The attacks target users searching for specific technical queries, showing malicious Google Ads that lead to Claude-generated artifacts containing malware. This represents a concerning abuse of AI-generated content for malware distribution.

    Sources:
    bleepingcomputer.com/news/secu
    cyberpress.org/malicious-campa
    rescana.com/post/claude-llm-ar
    news4hackers.com/clickfix-atta

    #Claude #MacMalware #Infostealer #GoogleAds #AI
    ----------

    ❄️ ShinyHunters Strikes Again: 600K Records Leaked ❄️

    The notorious ShinyHunters data extortion group claims to have stolen more than 600,000 Canada Goose customer records containing personal and payment-related information. Canada Goose told BleepingComputer the dataset appears to relate to past customer transactions and investigators have not found evidence of a breach of Canada Goose's own systems. The company is investigating whether the data came from a third-party vendor or partner.

    Sources:
    bleepingcomputer.com/news/secu
    securityaffairs.com/188046/dat
    techradar.com/pro/security/can
    vpncentral.com/canada-goose-60

    #DataBreach #CanadaGoose #ShinyHunters #CustomerData #CyberSecurity

  11. Evil Genius Chronicles Podcast for January 30 2026 - Fumble Fingered YutzDownload audio

    On this show, I play a song from Doctor Deathray; as I was upgrading the capacity of my Synology NAS I discovered I didn't need it; don't enable the trash can on your Time Machine drives on a NAS; I am using my extra capacity to self-host Mastodon; running a one person Mastodon instance is easier than I predicted; I love NTFY for notifications; I hate Apprise for notifications; I bought a Trezor hardware wallet to hold all my weird pockets of crypto; the UX of using crypto for anything sucks; Obsidian starts slow on my Android phone; Quick Draft for Obsidian solves a big problem for me.

    Here is the direct MP3 download for the Evil Genius Chronicles podcast, January 30 2026.

    Links mentioned in this episode:

    You can subscribe to this podcast feed via RSS. To sponsor the show, contact BackBeat Media. Don't forget, you can fly your EGC flag by buying the stuff package. This show as a whole is Creative Commons licensed Attribution-NonCommercial 4.0 Unported. Bandwidth for this episode is provided by Cachefly.

    #DoctorDeathray #SynologyNas #Mastodon #EllijayMakerspace #Fediback #Ntfy #Apprise #Trezor #Obsidian #QuickDraftForObsidian

  12. de mieux en mieux : meme les phisheurs surfent la vague du rapport d'Anthropic sur les cyberoperations automatisées par Claude avec cve bidon et tout.
    :blobcatfacepalm: :blobfacepalm:
    👀
    ⬇️
    lookyloo.circl.lu/tree/314e7e9

    #phishing #trezor

  13. Non mais LOLSOB 😅
    Je viens de recevoir la variante “Quantum” de la même campagne #phishing Trezor sur la meme adresse.

    Toujours le même domaine typo-squatté derrière — open-trezor[.]com — et le même redirect via Unbounce.
    👀 👇
    lookyloo.circl.lu/tree/a9e63b3

    #trezor #cyberveille

  14. Toujours etonné par la constance de cette campagne #phishing 🎣 #Trezor.
    Les acteurs derrière continuent à acheter du domaine typo-squatté et à peaufiner leurs scénarios de leurre à la sauce LLM, en surfant sur l’actu : du « quantum » jusqu’à cette fois, un faux incident de ransomware.

    On dirait bien que la campagne reste rentable, vu le soin apporté à chaque vague.

    Petit twist du jour : ils abusent maintenant du service Unbounce pour l’envoi et le redirect des faux boutons Update Firmware
    👀 👇
    lookyloo.circl.lu/tree/9ce187a

  15. Ledger Faces Backlash Over New Multisig App Fees Despite Technical Upgrade - Crypto hardware wallet maker Ledger is facing a wave of criticism following the ro... - cryptonews.com/news/ledger-fac #blockchainnews #ledgerwallet #ledger #trezor

  16. New Trezor Safe 7 Boasts Quantum-Resistant Design and Dual Secure Elements - Trezor has unveiled the Trezor Safe 7, a next-generation hardware wallet that intr... - news.bitcoin.com/new-trezor-sa #hardwarewallet #quantumattack #cryptonews #wallets #trezor

  17. [LIVE] Trezor Brings the Crypto Community to Prague to Redefine Bitcoin Ownership and Self-Custody - Crypto industry professionals and enthusiasts gathered in Prague today for the Trezor Con... - cryptonews.com/news/live-trezo #blockchainnews #trezor #news

  18. Trezor Launches MEV Protection for More Predictable Crypto Transactions - Trezor has introduced maximal extractable value (MEV) protection in Trezor Suite, ... - news.bitcoin.com/trezor-launch #cryptonews #blockchain #security #trezor

  19. Trevor has a where he keeps his treasures

  20. Users Can Connect to Uniswap, Aave, Opensea via Trezor Suite - Trezor Suite now supports Walletconnect, enabling users to connect their hardware ... - news.bitcoin.com/users-can-con #hardwarewallet #cryptonews #wallets #trezor

  21. le #phishing #trezor du jour
    variante habituelle:
    thématique "Integrity check" : link sendgrid --> nouveau domaine à bannir

    🎣 👀
    ⬇️
    lookyloo.circl.lu/tree/c5f2c7b

    #cyberveille

  22. Campagne de #phishing 🎣 en cours sur les portefeuilles crypto #Trezor

    Si vous avez acheté un Trezor, votre adresse mail est fort probablement dans une base de données qui circule.

    Depuis plusieurs semaines, une campagne de phishing très bien ciblée et agressive revient presque tous les jours.

    Leur thème préféré : fausse mise à jour de sécurité via un "avis important" rédigé en anglais, avec un lien raccourci (Sendgrid ou autre) qui redirige vers un domaine tout frais à thématique similaire (trezor-upgraade, -security...), très crédible visuellement.

    Le but : nous pousser à entrer le seed de récupération dans un faux site pour vider le portefeuille.

    👀 exemple du jour
    👇
    lookyloo.circl.lu/tree/6ff2dde

    signalements sur les réseaux
    ⬇️
    reddit.com/r/TREZOR/search/?q=
    ⬇️
    reddit.com/r/TREZOR/comments/1

    #cyberveille

  23. Trezor Co-Founder Launches Glok to Enhance Security for Bitcoin Users Against Rising Threats Such as Kidnappings - Alena Vranova, previously co-founder of Trezor, has announced the launch of GLOK, ... - news.bitcoin.com/trezor-co-fou #cybersecurity #newsbytes-5 #newsbytes #trezor

  24. ⚠️ Trezor’s legit support emails used in phishing scheme to steal wallet seeds.
    Even trusted addresses now require skepticism.
    🔗 bleepingcomputer.com/news/secu
    #crypto #phishing #trezor #cybersecurity

  25. Trezor Integrates Solana Staking via Partnership With Everstake - Trezor Suite has made it so solana ( SOL) holders can stake tokens directly from i... - news.bitcoin.com/trezor-integr #solana(sol) #cryptonews #trezor