GetChain News
中简 中繁 EN
GetChain News
Toggle sidebar
Trezor

Trezor

Active

Cryptocurrency hardware wallet

News Heat Trend

Project Overview

Trezor is a cryptocurrency hardware wallet that allows users to securely receive, store, and send cryptocurrencies. It is designed and marketed by SatoshiLabs.

The EU Cyber Resilience Act officially takes effect, requiring crypto wallet vendors to report vulnerabilities within 24 hours.

According to Cointelegraph, the EU Cyber Resilience Act (CRA) officially entered into force, requiring cryptocurrency hardware and software wallet providers to submit an early warning within 24 hours of discovering a serious security vulnerability or an actively exploited vulnerability, a complete notification within 72 hours, and a final report within 14 days after remediation measures are implemented. The regulation applies to all "products with digital elements" sold in the EU market. Violating companies face administrative fines of up to €15 million (approximately $17.3 million) or 2.5% of their global annual turnover, whichever is higher; providing false or misleading information will result in an additional fine of up to €5 million. Previously, Trezor and BitBox have both disclosed user data breach incidents and warned users to be vigilant against phishing emails disguised as security notifications.

Trezor Third-Party Email Service Provider Compromised, Phishing Emails Impersonate Official Communications

The official X account of Trezor (@Trezor) announced that its third-party email service provider was compromised by hackers, with a phishing email titled "Critical Security Alert: STM32 Entropy Vulnerability" circulating. Trezor explicitly clarified that the message was not sent by the company, and has urgently taken down the associated domains while launching an investigation. In recent days, Trezor had already suffered a customer data breach, resulting in the theft of the names, home addresses, and email addresses of approximately 67,000 users. Trezor advised users to avoid clicking any suspicious links and strictly refrain from disclosing their wallet mnemonics to anyone.

Trezor's Third-Party Email Service Provider Breached; Users Warned of "Critical Security Alert" Phishing Emails

Odaily News: Trezor stated that its third-party email service provider has been breached and is currently under investigation. It warns users not to click on links in fraudulent "Critical Security Alert" phishing emails. (Cointelegraph)

Independent verification scope expanded, Sparrow Wallet releases v2.5.4 security update

Odaily News: Sparrow Wallet v2.5.4 has been released following an extensive AI-assisted review, featuring multiple security hardening updates aimed at reducing users' reliance on external servers such as Electrum.Additionally, this version strengthens Ledger, Keycard, Trezor, Payjoin, PSBT, and multi-signature handling, removes Bitcoin Core credentials and other sensitive information from debug logs, restricts permissions for existing wallet and backup directories to owner-only access, closes residual local DNS resolution leaks when using Tor, and reinforces validation for wallet import, signing, downloads, and server responses. The update expands Sparrow Wallet's scope of independent verification for transaction data, hardware devices, and other inputs, reducing dependence on data provided by external servers. (Bitcoin News)

Coldcard incident boosts BitBox credit card sales by ~10x, while Trezor and OneKey see rising demand

Odaily News - Hardware wallet maker BitBox reports that credit card sales in August grew roughly 10x compared to the baseline of previous weeks, with the increase primarily driven by North America. Trezor and OneKey also confirmed rising sales during the same period, though neither disclosed specific figures.Trezor, BitBox, and OneKey have all re-reviewed their seed phrase generation, random number generator, entropy, and firmware verification processes. Trezor plans to conduct penetration testing on core firmware functions and publish related security audit reports. OneKey will strengthen reviews of security-critical code paths and transaction signing processes.Ledger CTO Charles Guillemet stated that AI-assisted attacks mean patch releases, vulnerability disclosures, and user education need to accelerate. Blockstream Jade has released a firmware update containing multiple fixes and recommends users simultaneously update their apps, operating systems, devices, routers, and home appliances. (Bitcoin.com News)

Rapid7 discloses crypto phishing campaign targeting 885,000 phone numbers and involving 5,576 Binance accounts

Odaily News Rapid7, a cybersecurity firm, has disclosed a crypto phishing campaign named Operation Asterix that targets approximately 885,000 phone numbers across multiple countries, redirecting victims to fraudulent wallet service websites. A total of 5,576 phone numbers have been matched with Binance user accounts and placed on the attack queue.The attackers steal seed phrases through fake apps impersonating Ledger, Trezor, and Exodus, while also contacting victims via fraudulent customer support emails and phone calls. Rapid7 also found that among over 316,000 phone numbers in Germany, 43,066 were matched with crypto trading accounts, representing a hit rate of approximately 13.6%.The related attacks also include a bulk phone number verification tool targeting Kraken accounts, and the investigation revealed that AI tools are being widely used in phishing operations. According to data from blockchain security firm Hacken, phishing attacks and social engineering scams caused $306 million in losses in the first quarter of this year, accounting for the majority of the $482 million total losses in the crypto industry. (Cointelegraph)

Approximately 233,000 Bitcoin moved as a precaution, with around $15 billion involved following the Coldcard exploit

Odaily News: After a firmware vulnerability in Coldcard hardware wallets was exploited, approximately 2,100 Bitcoin were stolen, with losses nearing $130 million. On-chain data shows that in the days surrounding the incident, wallets held by long-term holders transferred out approximately 233,000 Bitcoin, valued at around $15 billion. Casa CEO Nick Neuman stated that some of the transferred funds came from Coldcard users migrating to multi-signature wallets, with Ledger and Trezor users also taking similar measures after the event. During the same period, approximately 22,000 Bitcoin were transferred into exchanges. Coinkite has advised users who generated seed phrases using firmware versions 4.0.1 through 4.1.9 to treat their wallets as compromised and immediately migrate to new seed phrases. These versions cover the period from March 2021 to July 2026. (Decrypt)

Trezor: Approximately 10% of Global Crypto Users Self-Custody Their Private Keys

hardware wallet company Trezor stated there is a distinction between Bitcoin self-custody and holding Bitcoin credit exposure. When users store assets on exchanges, brokerages, or funds, they are actually relying on third-party ledger records and withdrawal arrangements. The company noted that after the full implementation of new EU crypto regulations, some exchanges that failed to obtain licenses in time have stopped offering regulated services to EU users. Trezor stated that its founders Marek Palatinus and Pavol Rusnák launched the first hardware wallet 12 years ago, moving private keys from internet-connected computers to dedicated devices. Trezor explained that private keys are generated on the device and never leave it, with transactions being signed inside the device before being sent. Trezor CCO Danny Sanders previously stated that if users put Bitcoin into ETFs and call it Bitcoin ownership, it would be one of the worst outcomes for the industry. Trezor estimates that among approximately 600 million global crypto users, about 10% self-custody their private keys, and around 12 to 13 million people use hardware wallets.

Trezor Exec: Putting All Bitcoin into ETFs Might Be the Worst Outcome for the Industry, Undermining the Core Principle of Self-Custody

: Danny Sanders, Chief Business Officer of hardware wallet manufacturer Trezor, stated that "putting everything into ETFs" might be the worst development path for the Bitcoin ecosystem. Since the launch of US spot Bitcoin ETFs in early 2024, cumulative inflows have exceeded $53 billion, making them a significant driver of BTC prices, but also potentially altering the structure of how users hold their assets.Sanders believes that over-reliance on ETFs will weaken Bitcoin's core principle of "self-custody," gradually shifting asset control to third-party institutions instead of users holding their private keys. Although self-custody carries risks such as lost seed phrases or unrecoverable private key leaks, he considers these more of a psychological barrier than a technical challenge, adding that "it's not difficult once you actually start doing it."Data shows that out of approximately 600 million crypto users globally, only about 10% practice self-custody, and only around 12 to 13 million users employ hardware wallets.As an early hardware wallet provider in the industry, Trezor helped popularize the BIP-39 seed phrase standard and continues to advocate for lowering the barriers to self-custody through improved user experience and educational tools, rather than relying on intermediary custody.Sanders concluded that the industry's long-term goal should be to gradually approach a Web2-level user experience, rather than simply replacing self-custody with ETFs. "That would probably be the worst possible outcome for the entire industry." (The Block)

The EU Cyber Resilience Act officially takes effect, requiring crypto wallet vendors to report vulnerabilities within 24 hours.

According to Cointelegraph, the EU Cyber Resilience Act (CRA) officially entered into force, requiring cryptocurrency hardware and software wallet providers to submit an early warning within 24 hours of discovering a serious security vulnerability or an actively exploited vulnerability, a complete notification within 72 hours, and a final report within 14 days after remediation measures are implemented. The regulation applies to all "products with digital elements" sold in the EU market. Violating companies face administrative fines of up to €15 million (approximately $17.3 million) or 2.5% of their global annual turnover, whichever is higher; providing false or misleading information will result in an additional fine of up to €5 million. Previously, Trezor and BitBox have both disclosed user data breach incidents and warned users to be vigilant against phishing emails disguised as security notifications.

Brevo Login Breach Leads to Phishing Emails Sent to 347,000 Trezor Subscribers, BitBox and CoinTracking Accounts Also Affected

Odaily News: A vulnerability in email platform Brevo's login system allowed attackers to access 138 customer accounts and send phishing emails to approximately 347,000 Trezor newsletter subscribers. Accounts belonging to BitBox and cryptocurrency portfolio and tax reporting platform CoinTracking were also used to send similar scam emails.Trezor stated that the phishing email was titled "Critical Security Alert: STM32 Entropy Vulnerability," with links pointing to an app that asked users to submit their wallet backups. Trezor disabled the relevant domain via DNS within 20 minutes, but approximately 2,500 people had visited the link, and the company has alerted all 347,000 subscribers to the risk.Brevo stated that attackers exploited a failure in single sign-on configuration permission boundaries to access all organizations reachable by invited users. Six accounts were used to send phishing emails, and contact data from 43 accounts was exported. BitBox and CoinTracking said they have found no evidence of leaked company credentials, funds, or recovery phrases, but are treating the affected email addresses as potentially compromised. (Cointelegraph)

Trezor Third-Party Email Service Provider Compromised, Phishing Emails Impersonate Official Communications

The official X account of Trezor (@Trezor) announced that its third-party email service provider was compromised by hackers, with a phishing email titled "Critical Security Alert: STM32 Entropy Vulnerability" circulating. Trezor explicitly clarified that the message was not sent by the company, and has urgently taken down the associated domains while launching an investigation. In recent days, Trezor had already suffered a customer data breach, resulting in the theft of the names, home addresses, and email addresses of approximately 67,000 users. Trezor advised users to avoid clicking any suspicious links and strictly refrain from disclosing their wallet mnemonics to anyone.

Coldcard incident boosts BitBox credit card sales by ~10x, while Trezor and OneKey see rising demand

Odaily News - Hardware wallet maker BitBox reports that credit card sales in August grew roughly 10x compared to the baseline of previous weeks, with the increase primarily driven by North America. Trezor and OneKey also confirmed rising sales during the same period, though neither disclosed specific figures.Trezor, BitBox, and OneKey have all re-reviewed their seed phrase generation, random number generator, entropy, and firmware verification processes. Trezor plans to conduct penetration testing on core firmware functions and publish related security audit reports. OneKey will strengthen reviews of security-critical code paths and transaction signing processes.Ledger CTO Charles Guillemet stated that AI-assisted attacks mean patch releases, vulnerability disclosures, and user education need to accelerate. Blockstream Jade has released a firmware update containing multiple fixes and recommends users simultaneously update their apps, operating systems, devices, routers, and home appliances. (Bitcoin.com News)

Cybersecurity company Rapid7 discloses encrypted phishing campaign targeting 885,000 phone numbers.

According to Cointelegraph, cybersecurity company Rapid7 has disclosed a cryptocurrency phishing campaign named "Operation Asterix" targeting approximately 885,000 phone numbers, aimed at luring users into visiting fraudulent Ledger, Trezor, and Exodus wallet apps or websites to steal mnemonic phrases and crypto assets.

Rapid7 discloses crypto phishing campaign targeting 885,000 phone numbers and involving 5,576 Binance accounts

Odaily News Rapid7, a cybersecurity firm, has disclosed a crypto phishing campaign named Operation Asterix that targets approximately 885,000 phone numbers across multiple countries, redirecting victims to fraudulent wallet service websites. A total of 5,576 phone numbers have been matched with Binance user accounts and placed on the attack queue.The attackers steal seed phrases through fake apps impersonating Ledger, Trezor, and Exodus, while also contacting victims via fraudulent customer support emails and phone calls. Rapid7 also found that among over 316,000 phone numbers in Germany, 43,066 were matched with crypto trading accounts, representing a hit rate of approximately 13.6%.The related attacks also include a bulk phone number verification tool targeting Kraken accounts, and the investigation revealed that AI tools are being widely used in phishing operations. According to data from blockchain security firm Hacken, phishing attacks and social engineering scams caused $306 million in losses in the first quarter of this year, accounting for the majority of the $482 million total losses in the crypto industry. (Cointelegraph)

Trezor supports clear signatures via ERC-7730

The Ethereum Foundation announced that Trezor now supports clear signing via ERC-7730. This feature aims to improve the readability of transaction content, helping users better understand what they are signing when transacting on Ethereum. Previously, the Ethereum Foundation's "Trillion Dollar Security Plan" detailed progress from the Clear Signing Working Group and encouraged more wallets and decentralized applications to participate in developing this standard.

Independent verification scope expanded, Sparrow Wallet releases v2.5.4 security update

Odaily News: Sparrow Wallet v2.5.4 has been released following an extensive AI-assisted review, featuring multiple security hardening updates aimed at reducing users' reliance on external servers such as Electrum.Additionally, this version strengthens Ledger, Keycard, Trezor, Payjoin, PSBT, and multi-signature handling, removes Bitcoin Core credentials and other sensitive information from debug logs, restricts permissions for existing wallet and backup directories to owner-only access, closes residual local DNS resolution leaks when using Tor, and reinforces validation for wallet import, signing, downloads, and server responses. The update expands Sparrow Wallet's scope of independent verification for transaction data, hardware devices, and other inputs, reducing dependence on data provided by external servers. (Bitcoin News)

Coldcard incident boosts BitBox credit card sales by ~10x, while Trezor and OneKey see rising demand

Odaily News - Hardware wallet maker BitBox reports that credit card sales in August grew roughly 10x compared to the baseline of previous weeks, with the increase primarily driven by North America. Trezor and OneKey also confirmed rising sales during the same period, though neither disclosed specific figures.Trezor, BitBox, and OneKey have all re-reviewed their seed phrase generation, random number generator, entropy, and firmware verification processes. Trezor plans to conduct penetration testing on core firmware functions and publish related security audit reports. OneKey will strengthen reviews of security-critical code paths and transaction signing processes.Ledger CTO Charles Guillemet stated that AI-assisted attacks mean patch releases, vulnerability disclosures, and user education need to accelerate. Blockstream Jade has released a firmware update containing multiple fixes and recommends users simultaneously update their apps, operating systems, devices, routers, and home appliances. (Bitcoin.com News)

Trezor to Introduce Anonymous Hardware Wallet Delivery Option, Supporting Nickname Orders and Unbranded Packaging

Odaily News: Bitcoin News posted on X platform that, after a logistics provider data breach exposed the personal information of 13,689 customers, Trezor stated it is prioritizing the launch of an "anonymous delivery" option. Users can place orders using a nickname or tag ID, have devices delivered to automated parcel lockers, and receive them in unbranded packaging, with purchase information not linked to home addresses or real identities. Trezor plans to roll out this option in the EU in September and in the US by the end of the year.

Approximately 233,000 Bitcoin moved as a precaution, with around $15 billion involved following the Coldcard exploit

Odaily News: After a firmware vulnerability in Coldcard hardware wallets was exploited, approximately 2,100 Bitcoin were stolen, with losses nearing $130 million. On-chain data shows that in the days surrounding the incident, wallets held by long-term holders transferred out approximately 233,000 Bitcoin, valued at around $15 billion. Casa CEO Nick Neuman stated that some of the transferred funds came from Coldcard users migrating to multi-signature wallets, with Ledger and Trezor users also taking similar measures after the event. During the same period, approximately 22,000 Bitcoin were transferred into exchanges. Coinkite has advised users who generated seed phrases using firmware versions 4.0.1 through 4.1.9 to treat their wallets as compromised and immediately migrate to new seed phrases. These versions cover the period from March 2021 to July 2026. (Decrypt)

Crypto Companies Send Joint Letter to AI Labs, Urging Access to Frontier Models for Bitcoin Developers

据 Cointelegraph 报道,比特币政策研究所(BPI)联合 Anchorage Digital、BitGo、Bitwise、Blockstream、Kraken、Ledger、MARA、Trezor 等多家加密机构,发布公开信敦促各大前沿 AI 实验室为比特币及开源软件开发者建立或扩展可信访问计划。 信中指出,Bitcoin Core 等开源维护者目前缺乏对 AI 实验室网络安全程序的访问渠道,被迫依赖能力较弱的开源模型,而比特币网络当前保护着逾 1 万亿美元资产,任何开源基础设施漏洞均可能危及用户毕生积蓄。BPI 同时披露,已收到多份报告显示包括潜在境外势力在内的复杂攻击者正借助先进 AI 能力持续发动攻击。

Related news

The EU Cyber Resilience Act officially takes effect, requiring crypto wallet vendors to report vulnerabilities within 24 hours.

According to Cointelegraph, the EU Cyber Resilience Act (CRA) officially entered into force, requiring cryptocurrency hardware and software wallet providers to submit an early warning within 24 hours of discovering a serious security vulnerability or an actively exploited vulnerability, a complete notification within 72 hours, and a final report within 14 days after remediation measures are implemented. The regulation applies to all "products with digital elements" sold in the EU market. Violating companies face administrative fines of up to €15 million (approximately $17.3 million) or 2.5% of their global annual turnover, whichever is higher; providing false or misleading information will result in an additional fine of up to €5 million. Previously, Trezor and BitBox have both disclosed user data breach incidents and warned users to be vigilant against phishing emails disguised as security notifications.

Brevo Login Breach Leads to Phishing Emails Sent to 347,000 Trezor Subscribers, BitBox and CoinTracking Accounts Also Affected

Odaily News: A vulnerability in email platform Brevo's login system allowed attackers to access 138 customer accounts and send phishing emails to approximately 347,000 Trezor newsletter subscribers. Accounts belonging to BitBox and cryptocurrency portfolio and tax reporting platform CoinTracking were also used to send similar scam emails.Trezor stated that the phishing email was titled "Critical Security Alert: STM32 Entropy Vulnerability," with links pointing to an app that asked users to submit their wallet backups. Trezor disabled the relevant domain via DNS within 20 minutes, but approximately 2,500 people had visited the link, and the company has alerted all 347,000 subscribers to the risk.Brevo stated that attackers exploited a failure in single sign-on configuration permission boundaries to access all organizations reachable by invited users. Six accounts were used to send phishing emails, and contact data from 43 accounts was exported. BitBox and CoinTracking said they have found no evidence of leaked company credentials, funds, or recovery phrases, but are treating the affected email addresses as potentially compromised. (Cointelegraph)

Trezor Third-Party Email Service Provider Compromised, Phishing Emails Impersonate Official Communications

The official X account of Trezor (@Trezor) announced that its third-party email service provider was compromised by hackers, with a phishing email titled "Critical Security Alert: STM32 Entropy Vulnerability" circulating. Trezor explicitly clarified that the message was not sent by the company, and has urgently taken down the associated domains while launching an investigation. In recent days, Trezor had already suffered a customer data breach, resulting in the theft of the names, home addresses, and email addresses of approximately 67,000 users. Trezor advised users to avoid clicking any suspicious links and strictly refrain from disclosing their wallet mnemonics to anyone.

Trezor's Third-Party Email Service Provider Breached; Users Warned of "Critical Security Alert" Phishing Emails

Odaily News: Trezor stated that its third-party email service provider has been breached and is currently under investigation. It warns users not to click on links in fraudulent "Critical Security Alert" phishing emails. (Cointelegraph)

Trezor and BitBox email infrastructure reportedly compromised

Odaily News: Joe Burnett, Vice President of Strive, posted on X platform that the email infrastructure of Trezor and BitBox appears to have been compromised, and the Bitcoin strengthening phase is still ongoing.

Trezor supports clear signatures via ERC-7730

The Ethereum Foundation announced that Trezor now supports clear signing via ERC-7730. This feature aims to improve the readability of transaction content, helping users better understand what they are signing when transacting on Ethereum. Previously, the Ethereum Foundation's "Trillion Dollar Security Plan" detailed progress from the Clear Signing Working Group and encouraged more wallets and decentralized applications to participate in developing this standard.