Back to News
SourceCointelegraph

Brevo login flaw enabled phishing email targeting 347K Trezor subscribers

Trezor told Cointelegraph that the phishing email was sent to 347,000 subscribers and said it is treating every address as “known to the attacker and possibly reusable for phishing.”
Disclaimer: The views above are the author's only and do not represent 711BTC. Nothing here constitutes investment advice.

Related

08-20 12:35

Cybersecurity firm unveils crypto phishing campaign targeting 885,000 phone numbers

Rapid7 unveiled a new cryptocurrency phishing campaign targeting 885,000 phone numbers, aiming to steal investors’ holdings by redirecting them to fake wallet provider websites.

07-01 01:38

Claude login emails expose "invisible location" feature, raising user privacy concerns about IP address-based location deduction.

According to Mars Finance, on July 1st, Beating's monitoring revealed that Anthropic's AI assistant Claude has recently sparked user discussion due to location hints in its login verification emails. Some users noticed that Claude includes a general login location, such as country, region, or city, when sending login verification codes or security alerts. This detail has brought renewed attention to how AI service providers identify the source of user access. Such locations are usually not precisely GPS-based, but rather inferred from IP addresses, network connections, and device information. When using VPNs, proxy servers, corporate networks, or mobile carrier networks, the location shown in the email may differ from the user's actual location. Anthropic's privacy policy states that the company collects IP addresses, device information, connection information, and locations inferred from IP addresses for security, fraud prevention, and enforcement of the terms of service. Claude users are particularly sensitive to this, partly because the service is not yet available in all regions, and cross-border use, overseas accounts, and third-party intermediary services are more common in the Chinese community. Recently, there have also been reports in the Chinese user community of accounts being suspended or requiring re-verification, which some users have dubbed a "ban wave."

09-09 23:02

Bitcoin Wallet Maker Trezor Says Hackers Breached Its Email Provider

The hardware wallet maker said a fake security alert claimed a hardware flaw could expose users’ recovery phrases.

09-10 05:34

Trezor, BitBox warn users about fake hardware wallet security alerts

BitBox said multiple Bitcoin companies appeared to have been targeted through a shared newsletter provider, while Trezor confirmed a breach at its email service.

09-04 11:19

Trezor says data breach affects another 67K US customers

Trezor said an additional 67,000 US users were affected by its shipping provider’s data breach, opening the path to potential phishing attacks and social engineering scams.

06-26 03:45Important

SlowMist: A new family of malware has emerged in the Go module ecosystem, targeting the developer environment of the Cosmos SDK project.

According to Foresight News , blockchain security company SlowMist tweeted that the Mini Shai-Hulud, Miasma, and Hades malware families have expanded from npm to the Go module ecosystem. The affected projects are specific versions based on the Cosmos SDK L1 project verana-labs/verana. The malicious code is hidden in an obfuscated form in the .claude/ directory and uses workflow hooks in VS Code and AI assistants, such as .claude/setup.mjs and .vscode/setup.mjs, to trigger execution when the developer opens the repository. This attack was not a traditional build-time supply chain attack, but rather an attack targeting the developer's local environment. The risk lies in the misuse of IDE automation and AI-assisted tools. Developers are advised to avoid opening untrusted repositories when IDE automation is enabled, and to focus on auditing .claude and .vscode related files, while also rotating potentially compromised credentials.