Data Protection & AI

Cryptocurrency wallet provider Trezor liable for damages from phishing attack

Regional Court for Civil Matters Vienna confirms claim for damages

In August 2024, the Regional Civil Court of Vienna handed down a landmark ruling concerning the legal consequences of a data breach and a phishing attack. The court ordered Trezor Company s.r.o., the manufacturer of a cryptocurrency hardware wallet, to pay damages (not legally binding).

phishing-attacks-cybersecurity-and-cryptocurrency

Table of Contents

Background of the case

In 2020, the plaintiff purchased a Trezor hardware wallet on which they stored cryptocurrencies (Bitcoin and Ethereum). In addition to the hardware wallet, the plaintiff also used the Trezor Suite software provided by the defendant to carry out transactions. In March 2022, MailChimp, the US company used by the defendant to manage its newsletters, fell victim to a cyberattack. During this attack, the plaintiff's email and IP addresses were also stolen.

A few days later, the plaintiff received a phishing email pretending that a security update was required for his wallet. Trusting the sender and the supposed urgency, the plaintiff followed the instructions in the email and entered his recovery seed after downloading fake software. Shortly thereafter, the plaintiff's crypto assets worth over 96,000 euros were transferred away by the unknown perpetrators.

Judicial decision and liability

The regional court found that Trezor Company is partially liable for the damage incurred, in particular because the plaintiff was not sufficiently informed that his personal data was transmitted to MailChimp, a US service provider. The court ruled that the defendant must pay half of the claimed amount to the plaintiff, but dismissed the rest of the claim. The court assumed contributory negligence on the part of the plaintiff, as he should have recognized the risks and the importance of the recovery seed.

Cybercrime in the crypto industry: A growing problem

This case illustrates the ongoing risks faced by cryptocurrency owners and the importance of privacy and data security. Despite a global decline in the total amount of stolen crypto assets to $1.7 billion in 2023, cyberattacks on crypto platforms and their users remain a significant problem. Particularly concerning is the increase in attacks where private keys are compromised.

Statute of limitations and recommended course of action for other victims

Affected Trezor customers who have suffered similar losses as a result of the phishing attack should note that claims for damages under Austrian law become time-barred after three years at the earliest, starting from the time they became aware of the damage and the tortfeasor. Injured parties can contact [taudes@atb.law] by calling 01 3912345 or by e-mail at Roman Taudes report to check your claims and, if necessary, assert claims for damages.

More articles

EU Commission CRA Guidelines

Cyber Resilience Act: EU Commission guidelines published

Get companies out of standby mode and into the fast lane for the CRA.
Picture of Stefan Knotzer
Stefan Knotzer

When the model sings: Copyright limits of AI training after the Suno ruling

Where AI & Copyright Hit a Sour Note
Picture of Stefan Knotzer
Stefan Knotzer
Laptop is losing data

Data Breach: The Devil Never Sleeps

What Austrian companies can learn from the incident at a major US law firm
Picture of Stefan Knotzer
Stefan Knotzer