Hardware wallets isolate the private key from offline equipment, but the purchase process leaves another risk. Vendors, retailers or logistics service providers usually have the name of the buyer, the mailbox, the mobile phone and the receiving address. Once such information is leaked, it is easier for the attackers to lock up the owners of the encrypted assets.

One thing needs to be distinguished first: the disclosure of user information does not mean that the wallet was broken. As long as there is no outflow of assistive words, private keys and backups, the attackers cannot initiate the transfer directly from the chain of names or addresses alone. More important than the immediate transfer of assets is to ascertain what information is leaked and to address the corresponding risks.

Let's make sure it's a leak or a key.

If it is the disclosure of sensitive information about a assistive word, a private key or other signatureable transaction, the asset is exposed to a direct risk and usually needs to move as soon as possible to a wallet generated by a new assistive word.

The situation is different if the customer database is leaked. Names, mailboxes, mobile phone numbers and receiving addresses cannot themselves sign a transaction, but are sufficient to allow the attackers to launch more accurate social workers ' attacks.

A typical case was that of Trezor in August. It states that the logistics service provider ShipMonk ' s system was not authorized to access information on 13,689 customers. Of these, 11,742 persons ' names, mailboxes, cell phone numbers and receiving addresses were exposed and 1,947 persons ' names, cities and mailboxes were affected. Trezor states that the hardware wallet, private key and backup are unaffected.

The most immediate risk is direct fishing. Fish

The most common threat after such incidents is fishing. Common group fishing tends to be more fragmented, but when the attackers have a real name, a brand name, a mailbox or even a receiving address, the disguised “security notice” becomes more real.

Common jargons include claims that the equipment was affected by the incident, requiring the user to “validate” the assistive words, to migrate to the new wallet, or to install so-called emergency solidware updates. The most important principle for users of hardware wallets is not to enter or provide assistive notes because of e-mail, text message, telephone or customer service requirements.

The assistive words themselves represent the control of the wallet. Anyone who gets a hand-in-the-hand is likely to rebuild his wallet elsewhere without having to get your physical equipment.

Postboxes and cell phone numbers need to be reinforced first.

If the leaked mailbox is also used on an exchange, bank or other important account, the security of the mailbox should be checked as soon as possible. Mailboxes are often the entry point for password replacement and account restoration, and may be used by the attackers to access additional services in the event of failure.

  • Replacement of more robust and unreusable stand-alone passwords for mailboxes
  • Open Multiple Identification
  • Check for abnormal login or forwarding rules

It is not necessary to change the mailbox immediately simply because the address of the mailbox appears in the leaked list. It is more critical to confirm that the password for the mailbox is not leaked and to raise the level of protection for the account itself.

The mobile phone leak would risk SIM changing cards. The attackers may impersonate the user and induce the operator to transfer the number to a SIM card under his control and then intercept the SMS authentication code and call.

Users can apply to the operator for additional protection, such as account PIN, trans-fixing, SIM change protection, or additional identification before modifying account information. At the same time, it would be useful to check whether important accounts continued to rely on SMS authentication codes and, to the extent possible, to move to more robust authentication.

The leak brings the risk to the line.

The leaking of the receiving address is more sensitive than the flow of regular Internet-based purchases, as it can send a clear signal to the attackers: The corresponding person at that address had voluntarily purchased and hosted the hardware wallet.

This does not indicate exactly how many encrypted assets are held by the holder, but it may be sufficient for the criminal to be targeted even if the amount is unknown. Underline security has been made a reality in recent years of robberies, house threats and kidnappings against encrypted asset holders.

For the majority of affected users, this does not mean that the risk is imminent, but it means that personal address privacy should be included in security considerations. Not to link the home address to the holding of encrypted assets on an open platform, but also to reduce the amount of information showing the size of the hold, high-priced consumption or other conjectureable asset levels.

Families should also be vigilant if they receive calls, visits or unusual deliveries from strangers claiming to be from a wallet company. For users with higher security requirements, future hardware wallets may also be purchased by taking into account self-depositation, e-mail collections, etc., to minimize the direct binding of address and secure product purchase records.