Tag: Hardware wallet security

  • Prosecutors Allege Cybercriminal Directed $2.6M Crypto Heist From Prison

    Prosecutors Allege Cybercriminal Directed $2.6M Crypto Heist From Prison

    Key Highlights

    • Incarcerated cybercriminal Robert Barr directed a crypto-theft syndicate from HMP Edinburgh between January and April 2024, targeting a local entrepreneur’s holdings valued at over $2.6 million.
    • Two home-invasion attempts failed: the first in January netted a hardware wallet but no PIN or recovery phrase; the second in April was foiled when the homeowner spotted intruders via a video doorbell camera.
    • Barr and accomplice Sean Favier have pleaded guilty to serious organized crime and attempted robbery charges; sentencing by Judge Lord Cubie is deferred pending background reports.

    Prison-Run Crypto Syndicate Targets Scottish Entrepreneur

    Prosecutors at the High Court in Edinburgh revealed on September 23 that Robert Barr, already serving sentences for fraud and illicit mobile-phone possession at HMP Edinburgh, orchestrated a sophisticated cryptocurrency theft operation from inside his cell. Between January and April 2024, Barr acted as the leader of an organized crime gang that twice attempted to raid the Midlothian home of an unnamed local entrepreneur who co-founded a startup and has been investing in digital assets since 2014.

    High-Value Target and Failed January Raid

    According to prosecution advocate David Dickson, Barr believed the victim’s cryptocurrency portfolio exceeded $2.6 million (£2 million), including $1.32 million in a self-created digital coin. During the initial break-in in January 2024, intruders stole a physical hardware wallet but were unable to access the funds because they lacked the device’s PIN and recovery seed phrase. Dickson told the court the assets remained secure despite the theft of the hardware itself.

    Technical Escalation: Remote Access and AnyDesk Deployment

    Undeterred, Barr organized a second attempt in April, this time instructing associates to gain remote control of the victim’s computers using remote-desktop software. Court documents read by prosecutors showed Barr messaging an accomplice: “When they’re in his house gonna need [to] get him on his PC fast [and] download AnyDesk rapid.” Barr also offered to join the raid via Telegram to guide the team through transferring the cryptocurrency once remote access was established.

    Video Doorbell Foils Second Attempt

    The April 17, 2024, operation collapsed when the homeowner spotted two men approaching and alerted his wife not to open the door. When she spoke through the video doorbell application, the suspects noticed the camera, attempted to conceal their faces, and fled the scene. The footage and subsequent investigation led authorities to seize an illicit mobile phone from Barr’s cell on June 25, 2024. Forensic analysis of that device uncovered extensive evidence of Barr organizing and providing technical support for crypto-theft schemes.

    Why This Matters

    The case highlights a growing intersection between traditional organized crime and cyber-enabled asset theft, demonstrating that incarceration does not necessarily neutralize sophisticated digital offenders. Barr’s ability to coordinate physical break-ins, direct remote-access tooling, and manage encrypted communications from a Scottish prison cell underscores the challenges correctional facilities face in contraband device detection and network monitoring. For the cryptocurrency sector, the episode reinforces the critical importance of multi-factor hardware wallet security—specifically, the protection of PINs and seed phrases—which rendered the stolen device useless to the thieves. Law-enforcement agencies across the UK are likely to cite this prosecution as a precedent for pursuing offenders who blend physical violence with advanced cyber tactics, and for seeking enhanced digital-forensics capabilities within prison environments.

    Frequently Asked Questions

    Who is Robert Barr and what has he pleaded guilty to?

    Robert Barr is a convicted fraudster who was serving time at HMP Edinburgh. He pleaded guilty at the High Court in Edinburgh to involvement in serious organized crime between January and April 2024, specifically directing a gang that attempted to steal cryptocurrency from a local entrepreneur.

    How much cryptocurrency was the target holding, and why was the first theft unsuccessful?

    Prosecutors estimated the victim’s holdings at over $2.6 million (£2 million), including $1.32 million in a self-created coin. The January break-in yielded a hardware wallet, but the thieves could not access the funds because they did not possess the device’s PIN or recovery seed phrase.

    What happened to the accomplices and when will sentencing occur?

    Accomplice Sean Favier pleaded guilty to attending the Midlothian property in an attempt to commit robbery and steal cryptocurrency assets. Judge Lord Cubie deferred sentencing for both Barr and Favier pending background reports; both men remain remanded in custody.

  • EU Cyber Resilience Act Requires 24-Hour Exploit Disclosure From Crypto Wallet Makers

    EU Cyber Resilience Act Requires 24-Hour Exploit Disclosure From Crypto Wallet Makers

    EU Cyber Resilience Act Imposes 24-Hour Vulnerability Reporting on Crypto Wallet Makers

    Crypto wallet manufacturers operating in Europe now face a strict 24-hour deadline to notify regulators when a vulnerability in their products is actively exploited. The requirement stems from Article 14 of the European Union’s Cyber Resilience Act (CRA), the bloc’s flagship cybersecurity legislation for connected hardware and software. The incident-reporting provisions took effect on September 11, 2026 — more than a year before the regulation’s broader security requirements become applicable in December 2027.

    What the 24-Hour Reporting Window Requires

    Article 14 of the Cyber Resilience Act covers manufacturers of “products with digital elements,” a category that encompasses hardware wallets and commercial wallet software because these products connect to devices and networks. When a manufacturer learns that a vulnerability is being actively exploited, it must submit an early warning notification to the EU’s cybersecurity agency ENISA and the designated computer security incident response team (CSIRT) through a single reporting platform within 24 hours.

    A fuller vulnerability notification follows within 72 hours, and a final report is due within 14 days of a corrective or mitigating measure becoming available. The same accelerated reporting rules apply to severe incidents affecting product security.

    Why the Deadline Matters for the Crypto Industry

    The reporting obligation arrives amid a series of high-profile wallet security failures. Hardware wallet maker Coldcard has spent recent weeks responding to attacks that drained Bitcoin from its devices, and the wave three exploiter has since moved funds through CoinJoin. Trezor, meanwhile, disclosed a ShipMonk data breach affecting thousands of US customers.

    Under the new EU regime, a manufacturer that discovers its firmware has been exploited must now alert regulators within a day rather than controlling the disclosure timeline itself. For an industry that has historically announced fixes on its own schedule, the requirement turns vulnerability disclosure from a discretionary choice into a legal duty.

    Compliance Timeline and Key Exemptions

    The September 11, 2026 date applies only to the CRA’s vulnerability and incident-reporting obligations. The regulation’s wider duties — including security-by-design requirements, conformity assessment, and CE marking — do not apply until December 11, 2027.

    The regime also includes relief for smaller firms: administrative fines do not apply to microenterprises and small enterprises that miss the 24-hour early-warning deadline, although the reporting obligation itself remains in force. Once the broader framework takes effect, non-compliance can draw enforcement action from national market surveillance authorities.

  • Trezor Warns Users After Hackers Breach Email Provider to Send Phishing Alerts

    Trezor Warns Users After Hackers Breach Email Provider to Send Phishing Alerts

    Trezor Warns Users of Phishing Campaign Exploiting Legitimate Email Infrastructure

    Hardware wallet manufacturer Trezor alerted users on Wednesday, September 9, 2026, about a sophisticated phishing campaign that exploited the company’s third-party email provider to distribute a fraudulent security notice. While Trezor wallets themselves remained unaffected, the attack targeted something more difficult to secure than software: user trust in communications from verified senders.

    Fabricated Vulnerability Sent from Verified Domain

    The phishing email carried the subject line: “Critical Security Alert: STM32 Entropy Vulnerability.” The message claimed Trezor engineers had discovered a design defect in STM32 chips used in the company’s products, warning that one in four devices could become compromised and that recovery phrases might lack sufficient randomness or entropy. This language closely mirrored issues described in the recent Coldcard firmware exploit.

    According to a report by Decrypt, Trezor identified the message as fraudulent and urged recipients not to click any links.

    Email Passed All Authentication Checks

    What made the campaign particularly effective was its delivery mechanism. One recipient reported the email originated from help@trezor.io, traversed the Sendinblue campaign infrastructure, and successfully passed DKIM, SPF, and DMARC authentication checks—technical validations typically used to verify sender legitimacy.

    Trezor confirmed it had disabled the domain used for the malicious alerts and launched an investigation into how threat actors accessed its legitimate sending infrastructure. The company issued its public warning shortly after 4:30 PM Eastern Time on September 9, just hours after users began reporting the suspicious emails.

    Broader Pattern Suggests Compromised Marketing Provider

    The breach may extend beyond Trezor. Nick Neuman, co-founder and CEO of Casa, indicated a similar trend appears to be affecting BitBox users, suggesting a common marketing email provider may have been compromised.

    This highlights a systemic vulnerability: wallet manufacturers can strengthen device security, but their brand reputation remains exposed through third-party dependencies—including email service providers, shipping partners, and payment processors—that they do not fully control.

    Distinction Between Data Breaches and Device Exploits

    Security analysts emphasize the critical difference between data breaches and device exploits. A previous Cryptopolitan report revealed phishing attempts against Ledger users have expanded into physical mail, yet these incidents compromise identity and contact information rather than directly exposing financial assets.

    The 2026 hardware wallet security landscape illustrates this distinction clearly:

    • SafePal disclosed an authorization error in an order tracking plugin exposed data for approximately 39,798 customers, confirming seed phrases, private keys, and wallet credentials were not compromised.
    • Trezor’s ShipMonk breach ultimately affected 80,689 customers after the company discovered legacy U.S. order records from 2019–2021 were also exposed.
    • Ledger’s Global-e incident in January exposed customer order details and contact information, though the exact number of affected users was not disclosed.

    In an August comparison, Memeburn correctly categorized Ledger, Trezor, and SafePal under “data breaches” while identifying Coldcard as a “device exploit.” The 13,689 figure Memeburn cited for Trezor predates the company’s September 4 update.

    Coldcard Exploit Represents Distinct Threat Category

    Coldcard stands apart from the data exposure incidents. According to Galaxy Research on August 14, the firmware flaw resulted in 190 confirmed victims, over 86,000 affected addresses, and at least $112.7 million (1,778.84 BTC) in stolen assets. Other estimates place potential losses near $130 million.

    Leaked Purchase Data Fuels Industrialized Phishing

    The danger of exposed shipping records lies in their utility for targeted attacks. Chainalysis estimated crypto scams and fraud stole $17 billion in 2025, with impersonation scams growing more than 1,400% year over year. The firm also found scams linked to AI vendors generated 4.5 times more revenue per operation than those without such connections.

    A hardware wallet purchase record—combining name, email, phone number, home address, and confirmation of crypto security device ownership—provides criminals with the context to craft highly convincing emails, calls, letters, or even physical approaches.

    Security Perimeter Extends Beyond the Device

    The lesson from Trezor’s latest incident is not that hardware wallets failed. It is that the security perimeter now encompasses the entire ecosystem surrounding them, and attackers increasingly need only a single trusted-looking message to breach defenses.

  • Solana Foundation Assesses $116M Coldcard Wallet Breach Impact

    Solana Foundation Assesses $116M Coldcard Wallet Breach Impact

    Coldcard Wallet Breach Drains $116 Million, Exposing Seed Phrase Vulnerabilities

    A significant security breach targeting Coldcard hardware wallets has resulted in approximately $116 million in losses, drawing sharp attention to fundamental weaknesses in crypto wallet security practices. The Solana Foundation disclosed the incident, attributing the exploit to guessable seed phrases that allowed attackers to compromise user funds.

    Attack Vector: Predictable Seed Phrases

    According to the Foundation’s analysis, the breach did not stem from a flaw in the Coldcard device firmware itself, but rather from users generating or storing seed phrases with insufficient entropy. Attackers were able to brute-force or guess these weak recovery phrases, effectively bypassing the hardware security model entirely. The incident underscores a persistent risk in self-custody: the human element of seed phrase generation and management.

    Solana Foundation CISO Weighs In on Systemic Risks

    Michael Coates, Chief Information Security Officer at the Solana Foundation, addressed the breach and its broader implications during an appearance on the Bits to Bricks podcast. Coates emphasized that the Coldcard hack serves as a critical case study for the entire digital asset ecosystem, revealing gaps that extend beyond any single hardware provider.

    Calls for Audits and Rapid Defense Mechanisms

    The Foundation is advocating for more rigorous security audits across wallet infrastructure and the implementation of rapid incident response frameworks. The goal is to detect and mitigate similar attack vectors before they scale. Coates stressed that proactive defense, including real-time monitoring for anomalous derivation path activity, must become standard practice for wallet manufacturers and integration platforms alike.

    Impact on User Trust and Institutional Adoption

    Security analysts warn that high-profile losses of this magnitude erode retail confidence and complicate institutional onboarding. Custody due diligence processes are likely to tighten, with allocators demanding verifiable entropy sources, multi-factor seed generation, and independent penetration test reports before approving hardware wallets for treasury use.

    Market Context and Trader Guidance

    While broader crypto market signals remain mixed, the Coldcard incident has elevated security to a primary narrative driver. Trading desks and portfolio managers are advised to monitor emerging wallet security standards and regulatory guidance closely. Shifts in user behavior toward audited, multi-sig, or MPC-based solutions may accelerate, influencing capital flows across custody providers and decentralized finance protocols.

    This article is for informational purposes only and does not constitute financial advice.

  • Ledger Denies Hack Claims as Patched Ethereum App Vulnerability Emerges

    Ledger Denies Hack Claims as Patched Ethereum App Vulnerability Emerges

    Ledger has denied hacking allegations following the publication of a laboratory demonstration showing a technical flaw in an outdated version of its Ethereum application. The hardware wallet manufacturer clarified on Thursday, August 27, 2026, that the security patch had been deployed prior to the public disclosure of the vulnerability.

    No Ledger user was hacked.
    What’s described here is a lab reproduction of a vulnerability in an outdated version of the Ethereum app.
    The issue was already identified through our security process and fixed in Ethereum app 1.22.2, released August 13, before this post. The…
    — Ledger (@Ledger) August 27, 2026

    Origin of the Controversy

    The controversy began when security researchers from rival firm OneKey posted on social media that they had successfully recreated an attack in a controlled lab setting. OneKey CEO Yishi Wang stated that the weakness stemmed from a race condition between the data buffer and the physical device’s visual interface. This flaw allowed an attacker with control over the intermediary software to overwrite a transaction while the user was reviewing the legitimate operation on screen. Technical data shared by the researchers indicates that this vector could redirect funds to external wallets without reflecting the modification on the physical device.

    Ledger’s Response and Technical Rebuttal

    Ledger’s Chief Technology Officer, Charles Guillemet, immediately rejected the narrative of a security breach in the manufacturer’s infrastructure. The company’s official documentation notes that reproducing a bug on an obsolete version within a lab does not constitute an active vulnerability or a compromise of user funds. The bulletin issued on August 27, 2026, specifies that an attack of this nature required the host computer to be previously compromised by malware or connected to a malicious web platform. Additionally, the technical report confirms that the private keys stored in the hardware’s secure element were never exposed.

    Patch Timeline and Technical Details of the Vulnerability

    The issue originated in the internal application designed to manage transactions on the Ethereum network and compatible tokens. In version 1.22.1, a malicious web application with permissions to connect to the device could send a secondary signing instruction while the user was examining the first.

    The manufacturer identified the issue internally and rolled out update 1.22.2 on August 13, 2026. The firm’s report details that the changes introduced two key safeguards: rejecting new signing sessions while a review is underway and voiding confirmations if the memory state differs from what is displayed on the screen.

    To secure the application ecosystem, the development team updated its software development kit (Secure SDK) to version 26.6.1 on August 21, 2026. Through this procedure, the company rebuilt the entire application catalog to prevent similar vectors across other digital assets.

    User Guidance and Ongoing Monitoring

    The Ledger Donjon security research team noted that this incident highlights the need for regular update practices on cold wallets. The modular hardware architecture allows patches to be applied to peripheral software without compromising the original recovery seed.

    To verify device protection, users should check in Ledger Live that the Ethereum app is updated to version 1.22.3 or higher. The manufacturer will continue monitoring its software repositories and will publish new update logs in its application manager during upcoming scheduled reviews.

  • Sparrow Bitcoin Privacy Wallet Releases Update After AI Flags Security Issues

    Sparrow Bitcoin Privacy Wallet Releases Update After AI Flags Security Issues

    Privacy-focused Bitcoin wallet Sparrow Wallet released version 2.5.4 on Thursday following an AI-assisted code review that produced the majority of the update’s fixes, developer Craig Raw told Decrypt.

    AI Review Prompted by Evolving Threat Landscape

    Raw said the review was driven primarily by the release of unrestricted Chinese AI models and the new ability to search large codebases for potential exploits. He did not identify the specific models used to review Sparrow’s code.

    The initiative followed a July attack that exploited a flaw in Coldcard’s seed-generation code. That vulnerability allowed an attacker to reconstruct private keys without physical access to the devices. Coldcard manufacturer Coinkite stated it believed AI may have helped the attacker discover the flaw.

    “Obviously, the Coldcard incident triggered a great deal of activity within the Bitcoin space itself, but it was really the sudden arrival of the capability to search large codebases for potential exploits,”

    Raw told Decrypt.

    Asked which fixes originated from the AI-assisted review, Raw replied:

    “Most of them—it was the bulk of the work in this release.”

    Key Security Enhancements in Version 2.5.4

    Launched in 2020, Sparrow Wallet provides privacy and security tools such as coin control, Tor support, and hardware wallet and air-gapped signing capabilities to keep private keys offline.

    The official changelog lists dozens of security changes designed to reduce trust in external services. Highlights include:

    • Verification that transactions returned by Electrum servers match the requested data.
    • Cryptographic proof checks that transactions were recorded in a Bitcoin block.
    • Verification of the latest chain block before displaying transactions as confirmed.

    BitBox02 hardware-wallet security is strengthened, now requiring firmware version 9.4.0 or later and anti-klepto protection to prevent a compromised device from leaking private-key information during signing.

    Additional changes affect Ledger, Trezor, and Keycard device handling, multisignature wallets, Payjoin, wallet imports, and partially signed Bitcoin transactions. The update also redacts Bitcoin Core credentials and other secrets from debug logs, restricts access to wallet and backup directories, and closes local DNS leaks when using Tor.

    No Evidence of Exploitation, but Update Recommended

    Raw emphasized that the volume of changes does not indicate an immediate threat to user funds.

    “Nothing was found that was likely to put funds at risk,”

    he said, adding that he personally reviewed each issue.

    “Every issue raised was carefully reviewed by myself, and multiple independent AI passes,”

    Raw stated.

    He reported no evidence that the issues were exploited or that Sparrow users were affected, and considers such exploitation unlikely. Nevertheless, he recommends installing the update, while acknowledging that users with air-gapped setups may hesitate to modify their configurations.

    “I always want people to update, and I recommend it—but of course there are those who are perhaps running Sparrow on air-gapped computers who are reluctant to make any changes to their setup,”

    Raw said.

    “In these cases, I would encourage reading the changelog regardless to make an informed choice.”

    Broader AI Security Push in Bitcoin Ecosystem

    Sparrow’s review reflects a wider trend across the Bitcoin ecosystem, where developers are increasingly using AI to scan wallets, payment protocols, and code libraries for vulnerabilities before attackers can exploit them.