Two incidents involving D’CENT and Trezor have highlighted how crypto users can be targeted through software, customer data and third-party suppliers, even when the security of the hardware wallets themselves has not been breached.
South Korean hardware-wallet company D’CENT is investigating unauthorised transfers from some users of its software-based App Wallet. Trezor, meanwhile, said attackers obtained 347,149 customer email contacts after compromising Brevo, its third-party marketing provider.
In both cases, the potential route to customers’ funds was the recovery phrase – the series of words that can recreate a wallet and provide control of its assets.
D’CENT investigates App Wallet transfers
D’CENT said it first received reports of unauthorised transfers on 16 September. Most of the affected users were using App Wallet, which stores or imports keys on a mobile phone.
The company has not confirmed any compromise of its hardware products and is continuing to investigate both the cause and the full scale of the transfers.
Its current investigation is focused on wallets whose recovery phrases were entered into App Wallet and which had a history of signing transactions on versions before 8.1.0, released on 5 November 2025. The potential exposure includes Bitcoin, Ethereum, XRP Ledger, Tron and other EVM-compatible networks.
A recovery phrase created on a D’CENT hardware device can recreate the same private keys if the words are later imported into software. D’CENT said that connecting a hardware device to its app normally does not transfer the phrase to a phone; the risk arises when users manually enter the phrase into App Wallet.
The company has advised users meeting its criteria to update the app before signing another transaction, create a new wallet with a fresh recovery phrase and move affected assets, rather than restoring the old phrase on another device. It is also working with exchanges, law enforcement and blockchain investigators to trace and potentially freeze stolen funds.
Trezor customers targeted through stolen contacts
The separate Trezor incident began with a breach at Brevo. The company said an attacker exploited a weakness in its SAML single-sign-on system to access 138 customer accounts. Contacts were exported from 43 accounts, while six were used to send phishing emails through legitimate customer infrastructure, allowing the messages to pass normal authentication checks.
The stolen Trezor data was used in a message claiming there was a critical hardware vulnerability. Recipients were told to download an application, which then requested their wallet backup. About 2,500 people reached the malicious domain before Trezor disabled it.
Trezor said clicking the link alone did not expose funds. The danger came if a user entered their backup phrase into the application, enabling an attacker to recreate the wallet elsewhere.
The email list could also support future scams built around security warnings, software updates or support requests. In August, a separate shipping-provider incident exposed Trezor customers’ phone numbers, shipping addresses and order information, although the company said its wallets were unaffected.
Trezor has suspended its Brevo account and is reviewing supplier relationships and security requirements. Brevo closed the exploited SSO route, reset active sessions and said it was introducing a permanent fix restricting authentication to the organisation controlling each SSO configuration.
D’CENT said it was adding safeguards and pre-release checks. Both companies continue to stress that recovery phrases should remain offline. Once entered into compromised software or disclosed through phishing, attackers do not need to defeat the hardware device itself.
