Trust becomes a weapon when even hardware wallet leaders and major platforms fall victim to sophisticated phishing campaigns.
Recent incidents reveal how attackers are weaponizing our trust in established crypto companies, turning brand reputation into their own asset:
Infrastructure Exploitation
Trezor’s support system was exploited recently: attackers abused legitimate contact forms to trigger authentic-looking auto-replies requesting wallet backups – demonstrating how even secure infrastructure can be manipulated. Meanwhile, Bybit lost $1.5 billion after attackers manipulated multi-signature wallet interfaces, showing users legitimate transactions while signing malicious ones behind the scenes.
Source: Cointelegraph – Trezor Phishing Warning
The Scale of the Crisis
The scale reveals a crisis of trust: over $1 billion lost to phishing across 296 incidents in 2024, with token transfer phishing achieving a devastating 62% success rate. Coinbase alone suffered a $400 million breach after attackers bribed overseas support contractors, while separate campaigns using fake coinbase-login.com sites cost users another $1.2 million. The FBI reported nearly 150,000 crypto-related phishing complaints in 2024 – a 66% year-over-year increase.
Sources:
Systematized Brand Impersonation
Brand impersonation has become systematized: 87% of fraud cases reported to California’s DFPI involved fake websites mimicking established platforms, while hundreds of malicious Facebook ads impersonated major exchanges like Binance and TradingView. Even Google Search results now regularly feature phishing links posing as legitimate crypto services, with Virtuals Protocol detecting three malicious links targeting their platform alone.
Sources:
The Investigation Challenge
At Recoveris, we know first-hand that the investigative challenge extends far beyond blockchain analysis – it requires comprehensive documentation of how attackers exploited legitimate infrastructure, coordinating OSINT research across multiple platforms to build evidence, taking into account both systemic vulnerabilities and individual user compromise.
The crypto industry’s trust infrastructure requires constant verification. Every interaction demands the same scrutiny we’d apply to unknown entities.
Are you adapting your security protocols as trusted brands become primary attack vectors?