{"id":157683,"date":"2025-06-24T13:30:22","date_gmt":"2025-06-24T13:30:22","guid":{"rendered":"https:\/\/cryptonews.com\/fr\/?p=157683"},"modified":"2025-06-24T13:30:22","modified_gmt":"2025-06-24T13:30:22","slug":"alerte-trezor-un-faux-support-client-qui-vide-les-portefeuilles","status":"publish","type":"post","link":"https:\/\/cryptonews.com\/fr\/news\/alerte-trezor-un-faux-support-client-qui-vide-les-portefeuilles\/","title":{"rendered":"Alerte Trezor : un faux support client qui vide les portefeuilles\u00a0"},"content":{"rendered":"<p>Trezor vient d\u2019\u00eatre indirectement impliqu\u00e9 dans une <strong>attaque de phishing<\/strong> d\u2019une rare subtilit\u00e9. L\u2019incident ne r\u00e9sulte pas d\u2019un piratage classique, mais de l\u2019exploitation fine d\u2019un outil souvent jug\u00e9 inoffensif : son formulaire de contact client. L\u2019objectif ? Inciter les victimes \u00e0 transmettre leur backup de portefeuille, c\u2019est-\u00e0-dire la cl\u00e9 ma\u00eetresse permettant d\u2019acc\u00e9der \u00e0 leurs crypto-actifs. <\/p><h2 class=\"wp-block-heading\">Un d\u00e9tournement de proc\u00e9dure, pas de technologie <\/h2><span class=\"replacer\"><\/span><p>C\u2019est un modus operandi des plus originaux qu&#8217;a \u00e9t\u00e9 utilis\u00e9 dans cette affaire. Les escrocs se sont servis d\u2019<strong>adresses e-mail d\u2019utilisateurs vol\u00e9es ou usurp\u00e9es<\/strong> pour envoyer de fausses demandes d\u2019assistance via le formulaire officiel de Trezor. En retour, le syst\u00e8me automatique du support a r\u00e9pondu avec des messages semblant l\u00e9gitimes, car \u00e9mis depuis l\u2019adresse r\u00e9elle de Trezor. <\/p><p>Ce qui rend cette attaque particuli\u00e8rement perverse, c\u2019est qu\u2019aucune intrusion technique n\u2019a eu lieu dans les serveurs de Trezor. <strong>Aucun piratage de base de donn\u00e9es<\/strong>, aucun contournement de firewall. Le point d\u2019entr\u00e9e est d\u2019une banalit\u00e9 effarante. Un simple <strong>formulaire de contact<\/strong> coupl\u00e9 \u00e0 un syst\u00e8me de r\u00e9ponse automatis\u00e9e pour d\u00e9rober l&#8217;un des <a href=\"https:\/\/blog.trezor.io\/trezor-wallet-backups-explained-bip-39-12-or-24-words-vs-slip-39-20-words-d7f2c5371569\" target=\"_blank\" rel=\"noreferrer noopener\">backups les plus s\u00e9curis\u00e9s du march\u00e9<\/a>. <\/p><h2 class=\"wp-block-heading\">Une le\u00e7on sur l&#8217;\u00e9volution des menaces <\/h2><span class=\"replacer\"><\/span><p>Ce n\u2019est donc <strong>pas une d\u00e9faillance du syst\u00e8me<\/strong> qui est mis en cause ici. C\u2019est plut\u00f4t l\u2019\u00e9cosyst\u00e8me de confiance qui gravite autour qui a \u00e9t\u00e9 savamment exploit\u00e9. <\/p><figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"683\" src=\"https:\/\/cimg.co\/wp-content\/uploads\/sites\/3\/2025\/06\/24133417\/9b9fb711-0830-42a6-b97b-c25b61a0c886.jpg-1024x683.jpg\" alt=\"\" class=\"wp-image-157763\" srcset=\"https:\/\/cimg.co\/wp-content\/uploads\/sites\/3\/2025\/06\/24133417\/9b9fb711-0830-42a6-b97b-c25b61a0c886.jpg-1024x683.jpg 1024w, https:\/\/cimg.co\/wp-content\/uploads\/sites\/3\/2025\/06\/24133417\/9b9fb711-0830-42a6-b97b-c25b61a0c886.jpg-300x200.jpg 300w, https:\/\/cimg.co\/wp-content\/uploads\/sites\/3\/2025\/06\/24133417\/9b9fb711-0830-42a6-b97b-c25b61a0c886.jpg-768x512.jpg 768w, https:\/\/cimg.co\/wp-content\/uploads\/sites\/3\/2025\/06\/24133417\/9b9fb711-0830-42a6-b97b-c25b61a0c886.jpg-1536x1024.jpg 1536w, https:\/\/cimg.co\/wp-content\/uploads\/sites\/3\/2025\/06\/24133417\/9b9fb711-0830-42a6-b97b-c25b61a0c886.jpg-2048x1365.jpg 2048w, https:\/\/cimg.co\/wp-content\/uploads\/sites\/3\/2025\/06\/24133417\/9b9fb711-0830-42a6-b97b-c25b61a0c886.jpg-450x300.jpg 450w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\"><\/figure><p>Cet incident a mis en lumi\u00e8re une tendance persistante en mati\u00e8re de <strong>cybers\u00e9curit\u00e9 crypto<\/strong>. D\u00e9sormais, la sophistication des attaques ne r\u00e9side plus seulement dans le code, mais int\u00e8gre des notions avanc\u00e9es de psychologie des masses.  <\/p><h2 class=\"wp-block-heading\">Trezor r\u00e9agit vite, mais le mal est fait<\/h2><span class=\"replacer\"><\/span><p>L\u2019exploitation du canal officiel d\u2019une entreprise comme Trezor donne \u00e0 ces messages frauduleux une aura de <strong>l\u00e9gitimit\u00e9 redoutable<\/strong>. M\u00eame des utilisateurs parmi les plus avertis n\u2019ont probablement pas rep\u00e9r\u00e9 la supercherie. En effet, comment se m\u00e9fier d\u2019un message provenant<strong> d\u2019une source authentifi\u00e9e<\/strong> (en apparence), mentionnant le nom de l\u2019agent, et suivant un format habituel.<\/p><p>Face \u00e0 cette situation, l\u2019entreprise se veut rassurante. Aucune donn\u00e9e sensible n\u2019a \u00e9t\u00e9 compromise en interne, et les \u00e9quipes ont imm\u00e9diatement <strong>d\u00e9sactiv\u00e9 l\u2019\u00e9l\u00e9ment du syst\u00e8me exploit\u00e9<\/strong>. Des filtres plus stricts sont \u00e0 l\u2019\u00e9tude pour \u00e9viter des abus similaires \u00e0 l\u2019avenir. <a href=\"https:\/\/cryptonews.com\/fr\/news\/service-client-trezor-fuite-donnees\/\">Comme en 2024 sur X<\/a>, Trezor en a \u00e9galement profit\u00e9 pour rappeler les bonnes pratiques en mati\u00e8re de s\u00e9curit\u00e9.  <\/p><figure class=\"wp-block-embed aligncenter is-type-rich is-provider-twitter wp-block-embed-twitter\"><div class=\"wp-block-embed__wrapper\">\n<blockquote class=\"twitter-tweet\" data-width=\"550\" data-dnt=\"true\"><p lang=\"en\" dir=\"ltr\">Important Update<br><br>We have identified a security issue where attackers abused our contact form to send scam emails appearing as legitimate Trezor support replies. <br><br>These scam emails appear legitimate but are a phishing attempt.<br><br>Remember, NEVER share your wallet backup \u2014 it must\u2026<\/p>&mdash; Trezor (@Trezor) <a href=\"https:\/\/twitter.com\/Trezor\/status\/1937085759028089100?ref_src=twsrc%5Etfw\">June 23, 2025<\/a><\/blockquote><script async src=\"https:\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script>\n<\/div><\/figure><h2 class=\"wp-block-heading\">Une vague d\u2019attaques en cascade sur l\u2019\u00e9cosyst\u00e8me <\/h2><span class=\"replacer\"><\/span><p>L\u2019affaire Trezor n\u2019est pas isol\u00e9e. Ces derni\u00e8res semaines, <strong>plusieurs plateformes majeures<\/strong> ont \u00e9t\u00e9 cibl\u00e9es. <\/p><p><strong>CoinMarketCap<\/strong> a vu son site infect\u00e9 par du code injectant de faux pop-ups de v\u00e9rification de portefeuille. R\u00e9sultat des courses, <strong>plus de 21 000 $ vol\u00e9s<\/strong> en quelques heures. <strong>Cointelegraph <\/strong>a \u00e9t\u00e9 la cible d\u2019un d\u00e9tournement de son interface pour afficher de <strong>faux airdrops<\/strong>. Les escrocs s&#8217;en sont servis ensuite pour inciter les utilisateurs \u00e0 connecter leur wallet \u00e0 des contrats malveillants. <\/p><p>En mars, <strong>Coinbase et Gemini<\/strong> ont vu leurs utilisateurs recevoir des e-mails encourageant une migration vers des portefeuilles d\u2019auto-conservation avec des <strong>liens pi\u00e9g\u00e9s<\/strong>. <\/p><p>Le point commun de tous ces \u00e9v\u00e8nements ? L\u2019attaque ne se cache plus derri\u00e8re des malwares, elle s\u2019ins\u00e8re dans des <strong>interfaces l\u00e9gitimes<\/strong>, les manipule, et exploite la confiance de la communaut\u00e9. <\/p><p>Les cold wallets ne sont pas <strong>infaillibles<\/strong>. Si l\u2019appareil en lui-m\u00eame est <strong>s\u00e9curis\u00e9, l\u2019utilisateur reste vuln\u00e9rable<\/strong> aux attaques le visant personnellement. <\/p><p>Les canaux officiels ne sont plus des zones s\u00fbres par d\u00e9faut. Il faudra d\u00e9sormais <strong>red\u00e9finir les r\u00e8gles de communication<\/strong> dans la crypto. <\/p><hr class=\"wp-block-separator has-alpha-channel-opacity\"><p>Sur le m\u00eame sujet : <\/p><ul class=\"wp-block-list\">\n<li><a href=\"https:\/\/cryptonews.com\/fr\/news\/entretien-exclusif-sebastien-martin-raid-square-securite-crypto\/\">Entretien exclusif avec S\u00e9bastien Martin, CEO de Raid Square, sur la s\u00e9curit\u00e9 en crypto<\/a><\/li>\n\n\n\n<li><a href=\"https:\/\/cryptonews.com\/fr\/news\/pascal-gauthier-ledger-stax\/\">Pascal Gauthier, PDG de Ledger : \u201cNous irons jusqu\u2019au bout pour sortir Stax\u201d<\/a><\/li>\n\n\n\n<li><a href=\"https:\/\/cryptonews.com\/fr\/news\/play-to-earn-playdapp-hackee\/\">La plateforme play-to-earn PlayDapp hack\u00e9e : 290 millions de dollars de jetons vol\u00e9s<\/a><\/li>\n<\/ul>","protected":false},"excerpt":{"rendered":"<p>Trezor vient d\u2019\u00eatre indirectement impliqu\u00e9 dans une attaque de phishing d\u2019une rare subtilit\u00e9. L\u2019incident ne r\u00e9sulte pas d\u2019un piratage classique, mais de l\u2019exploitation fine d\u2019un outil souvent jug\u00e9 inoffensif : son formulaire de contact client. L\u2019objectif ? Inciter les victimes \u00e0 transmettre leur backup de portefeuille, c\u2019est-\u00e0-dire la cl\u00e9 ma\u00eetresse permettant d\u2019acc\u00e9der \u00e0 leurs crypto-actifs. [&hellip;]<\/p>\n","protected":false},"author":663,"featured_media":157750,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[1,43],"tags":[],"editors":[2554],"sponsored_companies":[],"class_list":["post-157683","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news","category-technology-news","editors-ronan-gaillard"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.6 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Alerte Trezor : un faux support client vide les portefeuilles crypto<\/title>\n<meta name=\"description\" content=\"Un faux formulaire de contact Trezor pour voler des cryptomonnaies dans une attaque sophistiqu\u00e9e qui teste les limites de la s\u00e9curit\u00e9 crypto.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/cryptonews.com\/fr\/news\/alerte-trezor-un-faux-support-client-qui-vide-les-portefeuilles\/\" \/>\n<meta property=\"og:locale\" content=\"fr_FR\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Alerte Trezor : un faux support client vide les portefeuilles crypto\" \/>\n<meta property=\"og:description\" content=\"Un faux formulaire de contact Trezor pour voler des cryptomonnaies dans une attaque sophistiqu\u00e9e qui teste les limites de la s\u00e9curit\u00e9 crypto.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/cryptonews.com\/fr\/news\/alerte-trezor-un-faux-support-client-qui-vide-les-portefeuilles\/\" \/>\n<meta property=\"og:site_name\" content=\"Cryptonews France\" \/>\n<meta property=\"article:published_time\" content=\"2025-06-24T13:30:22+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/cimg.co\/wp-content\/uploads\/sites\/3\/2025\/06\/24125731\/1750769850-design-sans-titre-7.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"1200\" \/>\n\t<meta property=\"og:image:height\" content=\"800\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:title\" content=\"Alerte Trezor : un faux support client vide les portefeuilles crypto\" \/>\n<meta name=\"twitter:description\" content=\"Un faux formulaire de contact Trezor pour voler des cryptomonnaies dans une attaque sophistiqu\u00e9e qui teste les limites de la s\u00e9curit\u00e9 crypto.\" \/>\n<meta name=\"twitter:image\" content=\"https:\/\/cimg.co\/wp-content\/uploads\/sites\/3\/2025\/06\/24125731\/1750769850-design-sans-titre-7.jpg\" \/>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Alerte Trezor : un faux support client vide les portefeuilles crypto","description":"Un faux formulaire de contact Trezor pour voler des cryptomonnaies dans une attaque sophistiqu\u00e9e qui teste les limites de la s\u00e9curit\u00e9 crypto.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/cryptonews.com\/fr\/news\/alerte-trezor-un-faux-support-client-qui-vide-les-portefeuilles\/","og_locale":"fr_FR","og_type":"article","og_title":"Alerte Trezor : un faux support client vide les portefeuilles crypto","og_description":"Un faux formulaire de contact Trezor pour voler des cryptomonnaies dans une attaque sophistiqu\u00e9e qui teste les limites de la s\u00e9curit\u00e9 crypto.","og_url":"https:\/\/cryptonews.com\/fr\/news\/alerte-trezor-un-faux-support-client-qui-vide-les-portefeuilles\/","og_site_name":"Cryptonews France","article_published_time":"2025-06-24T13:30:22+00:00","og_image":[{"width":1200,"height":800,"url":"https:\/\/cimg.co\/wp-content\/uploads\/sites\/3\/2025\/06\/24125731\/1750769850-design-sans-titre-7.jpg","type":"image\/jpeg"}],"twitter_card":"summary_large_image","twitter_title":"Alerte Trezor : un faux support client vide les portefeuilles crypto","twitter_description":"Un faux formulaire de contact Trezor pour voler des cryptomonnaies dans une attaque sophistiqu\u00e9e qui teste les limites de la s\u00e9curit\u00e9 crypto.","twitter_image":"https:\/\/cimg.co\/wp-content\/uploads\/sites\/3\/2025\/06\/24125731\/1750769850-design-sans-titre-7.jpg","schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"NewsArticle","@id":"https:\/\/cryptonews.com\/fr\/news\/alerte-trezor-un-faux-support-client-qui-vide-les-portefeuilles\/#article","isPartOf":{"@id":"https:\/\/cryptonews.com\/fr\/news\/alerte-trezor-un-faux-support-client-qui-vide-les-portefeuilles\/"},"author":{"name":"Ronan Gaillard","@id":"https:\/\/cryptonews.com\/fr\/#\/schema\/person\/e78d0af0c40e9bd57dc648cd44641f43"},"headline":"Alerte Trezor : un faux support client qui vide les portefeuilles\u00a0","datePublished":"2025-06-24T13:30:22+00:00","mainEntityOfPage":{"@id":"https:\/\/cryptonews.com\/fr\/news\/alerte-trezor-un-faux-support-client-qui-vide-les-portefeuilles\/"},"wordCount":707,"publisher":{"@id":"https:\/\/cryptonews.com\/fr\/#organization"},"image":{"@id":"https:\/\/cryptonews.com\/fr\/news\/alerte-trezor-un-faux-support-client-qui-vide-les-portefeuilles\/#primaryimage"},"thumbnailUrl":"https:\/\/cimg.co\/wp-content\/uploads\/sites\/3\/2025\/06\/24125731\/1750769850-design-sans-titre-7.jpg","articleSection":["News","Technology News"],"inLanguage":"fr-FR","copyrightYear":"2025","copyrightHolder":{"@id":"https:\/\/cryptonews.com\/#organization"}},{"@type":"WebPage","@id":"https:\/\/cryptonews.com\/fr\/news\/alerte-trezor-un-faux-support-client-qui-vide-les-portefeuilles\/","url":"https:\/\/cryptonews.com\/fr\/news\/alerte-trezor-un-faux-support-client-qui-vide-les-portefeuilles\/","name":"Alerte Trezor : un faux support client vide les portefeuilles crypto","isPartOf":{"@id":"https:\/\/cryptonews.com\/fr\/#website"},"primaryImageOfPage":{"@id":"https:\/\/cryptonews.com\/fr\/news\/alerte-trezor-un-faux-support-client-qui-vide-les-portefeuilles\/#primaryimage"},"image":{"@id":"https:\/\/cryptonews.com\/fr\/news\/alerte-trezor-un-faux-support-client-qui-vide-les-portefeuilles\/#primaryimage"},"thumbnailUrl":"https:\/\/cimg.co\/wp-content\/uploads\/sites\/3\/2025\/06\/24125731\/1750769850-design-sans-titre-7.jpg","datePublished":"2025-06-24T13:30:22+00:00","description":"Un faux formulaire de contact Trezor pour voler des cryptomonnaies dans une attaque sophistiqu\u00e9e qui teste les limites de la s\u00e9curit\u00e9 crypto.","breadcrumb":{"@id":"https:\/\/cryptonews.com\/fr\/news\/alerte-trezor-un-faux-support-client-qui-vide-les-portefeuilles\/#breadcrumb"},"inLanguage":"fr-FR","potentialAction":[{"@type":"ReadAction","target":["https:\/\/cryptonews.com\/fr\/news\/alerte-trezor-un-faux-support-client-qui-vide-les-portefeuilles\/"]}],"author":[]},{"@type":"ImageObject","inLanguage":"fr-FR","@id":"https:\/\/cryptonews.com\/fr\/news\/alerte-trezor-un-faux-support-client-qui-vide-les-portefeuilles\/#primaryimage","url":"https:\/\/cimg.co\/wp-content\/uploads\/sites\/3\/2025\/06\/24125731\/1750769850-design-sans-titre-7.jpg","contentUrl":"https:\/\/cimg.co\/wp-content\/uploads\/sites\/3\/2025\/06\/24125731\/1750769850-design-sans-titre-7.jpg","width":1200,"height":800,"caption":"Un utilisateur qui se fait d\u00e9rober son wallet Trezor"},{"@type":"BreadcrumbList","@id":"https:\/\/cryptonews.com\/fr\/news\/alerte-trezor-un-faux-support-client-qui-vide-les-portefeuilles\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/cryptonews.com\/fr\/"},{"@type":"ListItem","position":2,"name":"Alerte Trezor : un faux support client qui vide les portefeuilles\u00a0"}]},{"@type":"WebSite","@id":"https:\/\/cryptonews.com\/fr\/#website","url":"https:\/\/cryptonews.com\/fr\/","name":"Cryptonews","description":"","publisher":{"@id":"https:\/\/cryptonews.com\/fr\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/cryptonews.com\/fr\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"fr-FR"},{"@type":"Organization","@id":"https:\/\/cryptonews.com\/fr\/#organization","name":"Cryptonews France","url":"https:\/\/cryptonews.com\/fr\/","logo":{"@type":"ImageObject","inLanguage":"fr-FR","@id":"https:\/\/cryptonews.com\/fr\/#\/schema\/logo\/image\/","url":"https:\/\/cryptonews.com\/wp-content\/uploads\/sites\/3\/2023\/09\/4.jpg","contentUrl":"https:\/\/cryptonews.com\/wp-content\/uploads\/sites\/3\/2023\/09\/4.jpg","width":1669,"height":874,"caption":"Cryptonews France"},"image":{"@id":"https:\/\/cryptonews.com\/fr\/#\/schema\/logo\/image\/"}}]}},"_links":{"self":[{"href":"https:\/\/cryptonews.com\/fr\/wp-json\/wp\/v2\/posts\/157683","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/cryptonews.com\/fr\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cryptonews.com\/fr\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/cryptonews.com\/fr\/wp-json\/wp\/v2\/users\/663"}],"replies":[{"embeddable":true,"href":"https:\/\/cryptonews.com\/fr\/wp-json\/wp\/v2\/comments?post=157683"}],"version-history":[{"count":4,"href":"https:\/\/cryptonews.com\/fr\/wp-json\/wp\/v2\/posts\/157683\/revisions"}],"predecessor-version":[{"id":157762,"href":"https:\/\/cryptonews.com\/fr\/wp-json\/wp\/v2\/posts\/157683\/revisions\/157762"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/cryptonews.com\/fr\/wp-json\/wp\/v2\/media\/157750"}],"wp:attachment":[{"href":"https:\/\/cryptonews.com\/fr\/wp-json\/wp\/v2\/media?parent=157683"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cryptonews.com\/fr\/wp-json\/wp\/v2\/categories?post=157683"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cryptonews.com\/fr\/wp-json\/wp\/v2\/tags?post=157683"},{"taxonomy":"editors","embeddable":true,"href":"https:\/\/cryptonews.com\/fr\/wp-json\/wp\/v2\/editors?post=157683"},{"taxonomy":"sponsored_companies","embeddable":true,"href":"https:\/\/cryptonews.com\/fr\/wp-json\/wp\/v2\/sponsored_companies?post=157683"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}