web3: Hardware wallet users face higher security risks after data breaches
TechCrunch
1h ago
Ai Focus
After the data of logistics partners Trezor and SafePal was leaked, hardware wallet users are at a higher risk of phishing and offline attacks.
Helpful
No.Help

近期两家物流公司接连发生数据泄露后,持有加密硬件钱包的用户面临新的安全压力。Trezor 与 SafePal 先后表示,数千名客户的个人信息和收货信息在各自物流合作方遭窃。外媒指出,事件没有直接影响钱包离线存储功能,但暴露了加密行业对外部供应链的依赖风险。

外泄信息指向真实住址

两家公司向物流方提供了寄送所需的姓名、家庭住址、邮箱和电话号码。这些信息一旦落入攻击者手中,风险并不只停留在垃圾邮件或诈骗电话层面。

更大的问题在于,攻击者可以据此识别哪些住址可能对应持有较多加密资产的用户,并进一步发起定向钓鱼,或把线上攻击转向线下威胁。

线下暴力索取助记词风险上升

报道提到,硬件钱包本身并未被远程攻破,但用户可能因此暴露在所谓“扳手攻击”之下。此类案件通常通过绑架、入室抢劫或暴力威胁,迫使受害者交出助记词,从而转走链上资产。

区块链安全公司 CertiK 表示,2025 年已确认数十起相关案件,较前一年增加 75%,被盗金额超过 4000 万美元。Chainalysis 给出的今年迄今统计接近 3000 万美元,部分团伙已使用绑架和入室方式索取助记词。

一旦攻击者掌握助记词,就能直接控制对应钱包中的加密资产,且链上转移通常无法撤回。

硬件钱包本身也出现新案例

除供应链泄露外,硬件钱包本身近期也出现新的安全事件。报道提到,本月早些时候,攻击者通过猜测 Coinkite 旗下 Coldcard 硬件钱包的密码,直接从链上盗走超过 1.3 亿美元加密资产。

报道称,攻击者能够预测部分 Coldcard 钱包离线生成的助记词。即便钱包和助记词从未接触互联网,攻击者仍可据此动态生成客户钱包密码,并直接转走链上资金。

Trezor 与 SafePal 也提醒用户警惕钓鱼攻击,包括通过短信、电话或电子邮件发送的定向信息。对硬件钱包用户而言,风险已不只来自设备本身,还来自物流、数据处理和售后联系等外围环节。

Tip
$0
Like
0
Save
0
Views 24
HQYC reminds readers to view blockchain rationally, stay aware of risks, and beware of virtual token issuance and speculation. All content on this site represents market information or related viewpoints only and does not constitute any form of investment advice. If you find sensitive content, please click“Report”,and we will handle it promptly。
Submit
Comment 0
Hot
Latest
No comments yet. Be the first!
Related
web3 : Strategy hasn't bought or sold Bitcoin for a consecutive week
Strategy has not traded Bitcoin for a consecutive week, and the market continues to pay attention to changes in their holdings.
Bitcoin Magazine
·2026-08-17 22:51:45
10
web3: MSCI plans to adjust rules, while Strategy and Metaplanet may be removed from the index
MSCI is proposed to be included in the index standards, while Strategy and Metaplanet may be excluded based on simulation results. The final decision is expected to be announced in October.
Coinpaper
·2026-08-17 22:22:05
16
web3: Coldcard Seed Vulnerability Exposed, Over 100 Million Dollars in Bitcoin Stolen
A vulnerability in hardware wallet seed generation has been alleged to have persisted for several years, with approximately 1,596 Bitcoins stolen, resulting in losses exceeding 100 million US dollars.
CoinDesk
·2026-08-17 22:10:12
19
web3 : Coinbase Users' stolen funds have been transferred to Tornado Cash again
Some of the funds related to the theft case of user Coinbase have been transferred back to Tornado Cash again, with the cumulative loss exceeding 300 million US dollars.
CoinPedia
·2026-08-17 21:59:40
24
web3: Bitcoin Falls Below Key Moving Averages, White House to Convene a Closed-door Meeting on Cryptocurrencies
Bitcoin falls below the 200-week moving average, ETF capital outflows increase; The White House will hold a closed-door meeting on cryptocurrencies, Coinbase betting on AI proxy payments.
U.Today
·2026-08-17 21:50:31
28
View More