• 6 mins read
  • Published

Crypto Hardware Wallets Face New Threats Beyond Device Security

Catheryne Nicholson Crypto infrastructure writer EgonCoin

Post by Catheryne Nicholson

Crypto Hardware Wallets Face New Threats Beyond Device Security EgonCoin © egoncoin.com
Crypto Hardware Wallets Face New Threats Beyond Device Security © egoncoin.com

Recent incidents at D'CENT and Trezor show that even when hardware wallets remain uncompromised, user assets can be exposed through software wallets and third-party data breaches that target recovery phrases and customer information.

Hardware wallets are often seen as the safest way to store cryptocurrency, but two recent cases show that the real risks can come from outside the device. This week, D'CENT and Trezor-both well-known hardware wallet makers-reported separate security incidents. In both cases, the hardware itself was not breached, but users still faced threats to their assets and personal data.

Recovery phrases at risk

D'CENT, a popular hardware wallet brand in South Korea, is investigating unauthorized transfers from users of its App Wallet, a software product that stores or imports private keys on mobile devices. The company first heard about suspicious activity on September 16. Most affected users had entered their recovery phrases into the App Wallet and were using versions earlier than 8.1.0, which was released on November 5, 2025. D'CENT has not found evidence that its hardware wallets were compromised. Instead, the incident highlights a key risk: importing a recovery phrase from a hardware wallet into a software wallet can open up new ways for attackers to steal funds. The exposure affects assets across Bitcoin, Ethereum, XRP Ledger, Tron, and other EVM-compatible networks.

"In just two hours, attackers drained over 2 million XRP from 1,552 D'CENT App Wallets, while hardware wallets remained unaffected."
EgonCoin Analyst

D'CENT now advises anyone who imported a recovery phrase into the App Wallet to update their app before making any more transactions, create a new wallet with a fresh recovery phrase, and move their assets to the new wallet. The company is working with exchanges, law enforcement, and blockchain investigators to track and possibly freeze stolen funds. The investigation is ongoing, and it is not yet clear how many addresses or assets can be recovered.

Third-party data breaches widen the attack surface

D'CENT has clarified that the abnormal transfers only affected the App Wallet, not hardware wallets. Users who only connected a hardware wallet and never imported their mnemonic phrase into the app do not need to take action. The risk comes when the same seed phrase is used in both the App Wallet and a hardware wallet, making users vulnerable if the software is compromised. Bitcoin.com covered the company's urgent advice to move funds to a trusted wallet or hardware device.

Trezor's recent incident was different. The breach happened at its third-party marketing provider, Brevo. Attackers exploited a flaw in Brevo's single-sign-on system, accessed 138 customer accounts, and exported contacts from 43 of them. For Trezor, this meant 347,149 marketing email contacts were exposed. Attackers used this information to send phishing emails that claimed there was a critical hardware vulnerability and urged recipients to download a fake application, which then asked for their wallet backup. Trezor reported that about 2,500 users visited the phishing site before it was taken down. Funds were only at risk if users entered their recovery phrases into the fake app, but the exposure of verified email addresses means users could be targeted by future phishing attempts.

"The Brevo breach did not compromise Trezor hardware wallets directly, but enabled attackers to send phishing emails to over 347,000 users. Brevo has since closed the exploited authentication route and logged out all users, with no direct evidence of stolen funds reported."
CoinDesk (source)

This is not the first time Trezor has dealt with a third-party data leak. In August, a shipping provider incident exposed customer identity and order details, including phone numbers and shipping addresses. Again, the hardware wallets themselves were not compromised. These events show how attackers can use information from outside a wallet maker's systems to identify crypto holders and craft convincing phishing attacks.

Security goes beyond the hardware

The D'CENT and Trezor incidents make it clear: hardware wallet security depends on the entire ecosystem. Both companies now face pressure to treat customer databases, vendor relationships, and companion software as part of their security responsibilities. Trezor has suspended its Brevo account and is reviewing its vendor security standards. Brevo has closed the exploited authentication route and is working on a permanent fix. D'CENT is adding new safeguards and verification steps as its investigation continues.

For users, the main lesson is to keep recovery phrases offline. Once a recovery phrase is entered into compromised software or a phishing site, the hardware wallet's protections no longer matter. As wallet makers compete, their ability to limit customer data, vet third-party vendors, and design software that avoids new risks will be just as important as the security of the hardware itself.

Reporting by EgonCoin notes that similar risks have appeared elsewhere in crypto, including malware that swaps out browser wallet extensions for credential-stealing copies, as reported earlier. These cases show that threats are not limited to direct device hacks, but can arise anywhere user credentials or recovery phrases are exposed.

Neither D'CENT nor Trezor has reported a direct compromise of their hardware wallets, but both have had to face the fact that user security is about more than secure chips and firmware. The real test for wallet providers is how well they can protect users from risks created by software, vendors, and data management. In a market built on trust, showing strong security across the board will decide which products users choose for their assets.

Hardware wallets are designed to keep private keys away from internet-connected devices, lowering the risk of remote attacks. But the recovery phrase-sometimes called a seed phrase-can restore the wallet and access its assets from any compatible device. If users enter this phrase into a software wallet or phishing site, attackers can bypass the hardware's protections. This trade-off between convenience and security is at the heart of self-custody: hardware wallets offer strong protection, but the human factor and the wider ecosystem remain ongoing sources of risk.

Related articles