Cryptelio

Hacks & Exploits

Recent Security Incidents Highlight Risks in Crypto Hardware Wallets

Cryptelio Editorial Published 18 Sep 2026 · 16:00 UTC

Recent incidents involving D’CENT and Trezor have underscored vulnerabilities in the security of crypto hardware wallets. D’CENT is investigating unauthorized transfers linked to its software-based App Wallet, while Trezor disclosed a breach that exposed customer email contacts.

D’CENT's Investigation into Unauthorized Transfers

D’CENT reported unauthorized transfers beginning on September 16, primarily affecting users of its App Wallet, which stores or imports keys on mobile devices. The company has not confirmed any compromise of its hardware wallets but is focusing on wallets where recovery phrases were entered into the App Wallet. Users are advised to update their app and create new wallets with fresh recovery phrases to mitigate risks.

Trezor's Data Breach and Phishing Threats

Trezor's breach involved an attacker exploiting a flaw in a third-party marketing provider, Brevo, leading to the export of 347,149 customer email contacts. Phishing emails were sent to users, claiming critical vulnerabilities and prompting them to download malicious applications. While Trezor stated that simply clicking the link did not compromise funds, entering backup information into these applications could allow attackers to recreate wallets.

Implications for Hardware Wallet Security

These incidents highlight the need for wallet manufacturers to enhance security measures, not just for their devices but also for customer databases and software workflows. Both D’CENT and Trezor are taking steps to improve their security protocols in response to these events. As the crypto landscape evolves, wallet makers must ensure that vulnerabilities in external systems do not compromise the integrity of their hardware wallets.

New Security Threats in Cryptocurrency

Recent reports indicate that hackers are force-installing malicious Chrome and Edge extensions that can steal sensitive information such as passwords and session data without user consent. This activity is linked to the KREMLIN bank malware toolkit, which has been involved in at least seven campaigns targeting 12 Brazilian banks since May 2025.

The infection typically begins when a user opens a JavaScript file disguised as a legitimate document, such as a bank receipt. Once the malware is activated, it manually copies an extension into the browser's profile directories and modifies the Secure Preferences file, allowing it to operate as if it were approved by the user.

Once installed, the malicious extension, which masquerades as AVSync, can perform a variety of harmful actions including stealing cookies, logging keystrokes, capturing screenshots, and intercepting HTTP traffic. Researchers from Elastic Security Labs have managed to disrupt this campaign by temporarily blocking over 1,500 infections, most of which originated from Brazil.

Impacted banks include major institutions such as Banco do Brasil, Caixa, Bradesco, Sicoob, C6 Bank, Inter, BTG, Safra, PagBank, PicPay, Santander, and Mercado Pago.

FAQ

What recent incidents have raised concerns about crypto hardware wallets?

Recent incidents involving D’CENT and Trezor have highlighted vulnerabilities in crypto hardware wallets, including unauthorized transfers linked to D’CENT's App Wallet and a data breach at Trezor that exposed customer email contacts.

What actions is D’CENT taking in response to unauthorized transfers?

D’CENT is investigating the unauthorized transfers and advises users to update their app and create new wallets with fresh recovery phrases to mitigate risks, although they have not confirmed any compromise of their hardware wallets.

What was the nature of the breach at Trezor?

Trezor's breach involved an attacker exploiting a flaw in a third-party marketing provider, Brevo, which led to the export of 347,149 customer email contacts and subsequent phishing emails targeting users.

What should Trezor users be cautious about following the breach?

Trezor users should be cautious of phishing emails that may prompt them to download malicious applications. While clicking the links does not compromise funds, entering backup information into these applications could allow attackers to recreate wallets.

What implications do these incidents have for hardware wallet security?

These incidents underscore the need for wallet manufacturers to enhance security measures for both their devices and customer databases. D’CENT and Trezor are taking steps to improve their security protocols in response to these vulnerabilities.

Read story →