{"id":9192,"date":"2024-03-23T01:22:31","date_gmt":"2024-03-23T01:22:31","guid":{"rendered":"https:\/\/www.bitrabo.com\/discover\/is-your-crypto-safe-trezor-addresses-concerns-over-hack-claims-sophisticated-phishing-scam\/"},"modified":"2024-03-23T01:22:31","modified_gmt":"2024-03-23T01:22:31","slug":"is-your-crypto-safe-trezor-addresses-concerns-over-hack-claims-sophisticated-phishing-scam","status":"publish","type":"post","link":"https:\/\/www.bitrabo.com\/discover\/is-your-crypto-safe-trezor-addresses-concerns-over-hack-claims-sophisticated-phishing-scam\/","title":{"rendered":"Is Your Crypto Safe? Trezor Addresses Concerns Over Hack, Claims \u201cSophisticated Phishing Scam\u201d"},"content":{"rendered":"<p style=\"font-weight: 400\">On March 19, Trezor\u2019s X suffered a security breach that exposed the account\u2019s 200,000 followers to a fake crypto presale. After the alarms were raised, most crypto users stayed vigilant while the hardware wallet company regained control.<\/p>\n<p style=\"font-weight: 400\">Trezor\u2019s team recently published a preliminary report addressing the concerns. The post also explained the elaborate phishing scam that bypassed the company\u2019s security measures.<\/p>\n<h2 style=\"font-weight: 400\"><span class=\"ez-toc-section\" id=\"Is_Trezors_%E2%80%9CUnwavering_Security%E2%80%9D_Still_Protecting_Your_Crypto\"><\/span>Is Trezor\u2019s \u201cUnwavering Security\u201d Still Protecting Your Crypto?<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p style=\"font-weight: 400\">After gaining control of the account, the hacker posted a fake presale address for a $TRZR token. Disguised as an \u201cinitiative\u201d to help the Slerf community, the post offered a \u201cseparate bonus airdrop\u201d from a website linked in the post that redirected to a wallet drainer.<\/p>\n<p style=\"font-weight: 400\">After Trezor regained control of the account, X users expressed their worries about the incident and suggested that the hack was a \u201cbad look\u201d on the security-focused company. However, the company guaranteed that they had \u201crobust security measures.\u201d<\/p>\n<blockquote>\n<p>We want to clarify that we do not make use of SMS for 2FA, and instead employ more secure methods of authentication.<\/p>\n<\/blockquote>\n<p style=\"font-weight: 400\">The company finally <a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/blog.trezor.io\/update-addressing-concerns-around-our-recent-x-twitter-account-breach-a888bc349007\">addressed<\/a> users\u2019 concerns in a preliminary report. The hack is possible due to a \u201csophisticated phishing scam\u201d instead of a lack of basic security measures.<\/p>\n<p style=\"font-weight: 400\">The company is based on \u201cunwavering security,\u201d the post states; as such, all products and internal systems remain unaffected despite the breach.<\/p>\n<p><\/p>\n<h2 style=\"font-weight: 400\"><span class=\"ez-toc-section\" id=\"Sophisticated_Phishing_Scam_Steals_Pocket_Change\"><\/span>Sophisticated Phishing Scam Steals Pocket Change<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p style=\"font-weight: 400\">According to Trezor, the ongoing investigation has revealed that \u201cthe breach appears to have arisen from a sophisticated and calculated phishing attack that was in the works for weeks.\u201d<\/p>\n<p style=\"font-weight: 400\">The calculated scheme began on February 29 after the attacker posed for a \u201ccredible entity\u201d from the crypto industry. At the time of writing, the identity of the impersonated figure was not revealed.<\/p>\n<p style=\"font-weight: 400\">The attacker contacted Trezor\u2019s PR team through X using a \u201cwell-crafted social media presence.\u201d The seemingly genuine contact aimed to schedule an interview with the company\u2019s CEO.<\/p>\n<p style=\"font-weight: 400\">According to the report, the attacker and the team had a back-and-forth conversation over several days, which made the efforts to stage a call seem more credible. However, the call agreement led to the click of the link that granted access to Trezor\u2019s X account.<\/p>\n<p style=\"font-weight: 400\">The malicious link was disguised as a Calendly invite that, upon clicking, redirected a Trezor\u2019s team member to a page requesting the X login credentials. The team rescheduled the call as the incident raised red flags.<\/p>\n<p style=\"font-weight: 400\">During the rescheduled call, the attacker pretended to have technical issues and urged Trezor\u2019s team member \u201cto \u2018authorize\u2019 joining the call.\u201d This authorization connected the hacker\u2019s Calendly app with the company\u2019s X account. As a result, the attacker gained access to the account and published the now-deleted posts.<\/p>\n<blockquote class=\"twitter-tweet\" data-width=\"500\" data-dnt=\"true\">\n<p lang=\"en\" dir=\"ltr\">he got a whopping 0.96 Solana as well <a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/t.co\/zqHjxM8EOI\">pic.twitter.com\/zqHjxM8EOI<\/a><\/p>\n<p>&mdash; xc (@Theft) <a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/twitter.com\/Theft\/status\/1770237549547802922?ref_src=twsrc%5Etfw\">March 19, 2024<\/a><\/p>\n<\/blockquote>\n<p style=\"font-weight: 400\">The hacker only stole $8,100 from the malicious link redirecting to the wallet drainer. \u00a0Impressively, just 0.96 SOL (around $162,4 at writing time\u2019s pricing) were sent to the fake presale address.<\/p>\n<p style=\"font-weight: 400\">Undoubtedly, the attack was a calculated and elaborate scheme that aimed to become a big heist. However, the hacker\u2019s attempt was halted by the crypto community surveillance and the suspicious nature of the unauthorized posts.<\/p>\n<p><img fetchpriority=\"high\" decoding=\"async\" class=\"size-large wp-image-288958 aligncenter\" src=\"https:\/\/www.bitrabo.com\/discover\/wp-content\/uploads\/2024\/03\/1711156951_327_Is-Your-Crypto-Safe-Trezor-Addresses-Concerns-Over-Hack-Claims.png\" alt=\"BTC,BTCUSDT, crypto scam, trezor\" width=\"980\" height=\"493\" data-recalc-dims=\"1\" \/><\/p>\n<p><script async src=\"https:\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script><\/p>\n","protected":false},"excerpt":{"rendered":"<p>On March 19, Trezor\u2019s X suffered a security breach that exposed the account\u2019s 200,000 followers to a fake crypto presale. After the alarms were raised, most crypto users stayed vigilant while the hardware wallet company regained control. Trezor\u2019s team recently published a preliminary report addressing the concerns. The post also explained the elaborate phishing scam [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":9193,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"slim_seo":{"title":"Is Your Crypto Safe? Trezor Addresses Concerns Over Hack, Claims \u201cSophisticated Phishing Scam\u201d - Bitrabo","description":"On March 19, Trezor\u2019s X suffered a security breach that exposed the account\u2019s 200,000 followers to a fake crypto presale. After the alarms were raised, most cry"},"footnotes":""},"categories":[316],"tags":[1576,741,559,504,1430,2630,861,637,2756,2755],"class_list":["post-9192","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-crypto-news","tag-addresses","tag-claims","tag-concerns","tag-crypto","tag-hack","tag-phishing","tag-safe","tag-scam","tag-sophisticated","tag-trezor"],"acf":[],"_links":{"self":[{"href":"https:\/\/www.bitrabo.com\/discover\/wp-json\/wp\/v2\/posts\/9192","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.bitrabo.com\/discover\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.bitrabo.com\/discover\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.bitrabo.com\/discover\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.bitrabo.com\/discover\/wp-json\/wp\/v2\/comments?post=9192"}],"version-history":[{"count":0,"href":"https:\/\/www.bitrabo.com\/discover\/wp-json\/wp\/v2\/posts\/9192\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.bitrabo.com\/discover\/wp-json\/wp\/v2\/media\/9193"}],"wp:attachment":[{"href":"https:\/\/www.bitrabo.com\/discover\/wp-json\/wp\/v2\/media?parent=9192"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.bitrabo.com\/discover\/wp-json\/wp\/v2\/categories?post=9192"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.bitrabo.com\/discover\/wp-json\/wp\/v2\/tags?post=9192"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}