D’CENT and Trezor disclosed separate security breaches this week, both creating pathways to user recovery phrases without compromising the hardware devices themselves.
D’CENT, a hardware wallet manufacturer, received the first reports of unauthorized transfers from its software wallet on September 16. The company stated that manually importing a recovery phrase generated on D’CENT hardware into its App Wallet transfers that phrase to the user’s phone, whereas normal hardware connection does not. Affected networks include Bitcoin, Ethereum, XRP Ledger, Tron, and EVM-compatible networks.
D’CENT stated it is adding safeguards and pre-release verification procedures in response. The company did not specify the total number of users affected or the total value of stolen assets.
Trezor, another hardware wallet manufacturer, separately disclosed a breach involving Brevo, a third-party marketing provider. An attacker exploited a flaw in Brevo’s SAML single-sign-on implementation, compromising 138 customer accounts at Brevo. From those accounts, 43 were used to export 347,149 customer email contacts from Trezor’s systems. The attacker then used 6 Brevo accounts to send phishing emails to Trezor customers.
The phishing emails claimed a critical hardware vulnerability and requested users download their wallet backup. Trezor stated that clicking the link alone did not expose funds; risk arose only if a user entered their backup into the malicious application. Before Trezor disabled the malicious domain, 2,500 recipients had reached it. Trezor did not state whether any of those recipients actually entered backup information into the application.
Trezor had suspended its Brevo account and is reviewing vendor relationships. The company also disclosed that a shipping provider breach in August exposed customer identity and order information.
Both incidents highlight a structural weakness in hardware wallet security: recovery phrases, which reconstruct private keys outside the device, depend entirely on user discipline to remain offline. Neither D’CENT nor Trezor can enforce that discipline through hardware alone. Both companies depend on users keeping recovery phrases offline and not entering them into software applications, even when prompted by seemingly official communications.