Separate data leaks from Trezor and SafePal hardware wallet providers have exposed customer information, triggering a phishing wave targeting holders. Coinkite separately warned Coldcard Mk3 users of a potential seed-generation vulnerability.
Hardware wallet manufacturers store customer purchase records, email addresses, and shipping data—all intelligence useful for phishing campaigns. A breach of a hardware wallet provider means attackers know who holds crypto and where they physically live.
As institutions adopt crypto custody, hardware wallet ecosystem security becomes systemic risk. A single manufacturer vulnerability or data leak can compromise billions in holdings if users are tricked into revealing seed phrases via convincing phishing.
Update Ledger apps immediately, monitor email for phishing attempts, enable 2FA on all exchange accounts, and consider airgapped signing for large holdings. Watch for further Trezor and SafePal advisories as investigations continue.
Read More →