Ich war natürlich auch betroffen aber am 10. September kam dann die Aufklärung (per Mail).
Dear CoinTracking user,
A few hours ago, an unauthorized third party gained access to our account at our email provider Brevo and sent a phishing email to some CoinTracking users. It appeared to come from
support@cointracking.info and used our design, but it was not sent by us.
The fake email has the subject "Data Breach Notice: Please refresh API Keys as soon as possible", claims a "January 2026 data breach" exposed your xPub keys, and asks you to "Generate New Keys" via redirect-cointracking.com. None of this is true, and that domain is not ours.
According to reports, similar messages were also sent to customers of Trezor and BitBox, who use the same email provider, Brevo. Please be aware that other companies may be affected as well and treat comparable "security notices" from any crypto service with the same caution.
If you received it: do not click, do not reply, do not send crypto. Delete it.
If you only read it: no action needed.
If you entered a seed phrase or private key: treat the wallet as compromised and move your funds to a new wallet with a new seed phrase immediately.
If you entered your CoinTracking login: change your password and enable 2FA.
The account is secured and we are investigating with the service providers involved. We apologize for the concern this has caused.
CoinTracking never holds your funds or private keys and will never ask you to send crypto, enter a seed phrase, or regenerate keys.
If you have any questions or are unsure whether an email is really from us, please contact our support team directly via our Help Center.
We take this incident very seriously and will share further findings as our investigation progresses.
Thank you for your trust.
Auffällig war mir im ersten Moment eigentlich nur folgende Passage in der ersten Nachricht: "
You can also copy and paste this link into your browser: https://redirect-cointracking.com"
(Achtung: SCAM!)Beim Aufruf von dieser Seite hat Firefox direkt Alarm gemeldet. Sonst war das aber leider echt gut gemacht.
@Lakai01
Das ist top.
Da hat dein Programm bzw. dein Provider wohl die passenden Sicherheitsmechanismen implementiert um den falschen Absender (auch wenn sie die korrekten Brevo Daten hatten) zu erkennen - nicht schlecht.