Crypto news report · source clearly identified
Hardware Wallet Security Can Remain Intact Even When Surrounding Systems Fail
Recent incidents at D CENT and Trezor highlight how breaches in software and third‑party services can expose recovery phrases, but the hardware devices themselves remain uncompromised.

Two recent security incidents involving popular hardware‑wallet providers demonstrate that the greatest risks to self‑custody often lie outside the physical device. While neither D CENT nor Trezor reported a direct compromise of their hardware, attackers leveraged software‑based weaknesses to target users’ recovery phrases.
D CENT App Wallet Breach
On September 16, D CENT received reports of unauthorized transfers from users of its App Wallet, a mobile application that can store or import private keys. The investigation identified affected wallets that met two criteria:
- Recovery phrases had been manually entered into the App Wallet.
- Transactions were signed with app versions earlier than 8.1.0 (released November 5, 2025).
The exposure spans multiple networks, including Bitcoin, Ethereum, XRP Ledger, Tron and other EVM‑compatible chains. D CENT advises users who match these criteria to update the app, generate a new wallet with a fresh recovery phrase, and move assets rather than restoring the old phrase on another device.
Trezor Marketing‑Data Breach
Trezor’s incident originated from a breach of its third‑party marketing provider, Brevo. An attacker exploited a flaw in Brevo’s SAML single‑sign‑on, gaining access to 138 customer accounts and exporting 347,149 email contacts. Using the compromised list, attackers sent phishing emails that appeared to come from Trezor’s own infrastructure, claiming a critical hardware vulnerability and prompting recipients to download a malicious application that requested wallet backups.
Approximately 2,500 recipients visited the malicious site before Trezor disabled it. The attack did not directly steal funds; however, any user who entered their recovery phrase into the fake application would have handed the attacker the keys needed to reconstruct the wallet.
Implications for Self‑Custody Security
Both incidents underscore that:
- Recovery phrases entered into software or disclosed via phishing become the weakest link, regardless of hardware robustness.
- Vendor‑side data (email addresses, shipping details) can be weaponized to craft convincing attacks.
- Hardware‑wallet manufacturers must extend security programs to include companion software, customer databases, and third‑party service providers.
Trezor has suspended its Brevo account and is reviewing vendor relationships, while Brevo has closed the exploited SSO route and implemented stricter authentication controls. D CENT is adding safeguards to its app and pre‑release verification processes.
What Users Should Do
- Keep recovery phrases offline and never import them into software unless absolutely necessary.
- Update wallet applications promptly and avoid using outdated versions.
- Be wary of unsolicited emails claiming urgent security issues, especially those requesting wallet backups.
- Consider generating a new recovery phrase and migrating assets if there is any suspicion of compromise.
Source & attribution
News Source
- Publisher
- CryptoSlate
- Original date
- September 18, 2026, 11:50 AM
- Original headline
- Your crypto hardware wallet can stay secure while everything around it fails