Your signal. Your price.
Non-custodial payment processor Swiss Bitcoin Pay temporarily shut down its servers following a data breach that leaked customer emails, Bitcoin addresses, and IBANs. This event follows recent security breaches at both Revolut and hardware wallet manufacturer Trezor.
Attackers breached email marketing service Bravo to send highly convincing phishing emails to Trezor and BitBox users. By exploiting valid API keys, the phishes successfully bypassed standard SPF and DKIM email authentication checks.
Trezor and BitBox warned users of phishing emails sent via compromised third-party newsletter services. The fraudulent security alerts falsely claimed devices suffered from an entropy vulnerability.
Ledger CTO Charles Gilmette argues that artificial intelligence has simplified bug discovery, prompting some researchers to publish vulnerabilities prematurely to gain attention. Gilmette and Trezor security head Jan Komarek advocate for a standard 90-day private disclosure window to develop patches.
Trezor's shipping partner, ShipMonk, leaked customer records of approximately 67,000 US customers, bringing the total exposed to 80,000. The leak included names, physical addresses, phone numbers, and email addresses, highlighting shipping data risks.
Cake Wallet 6.4.4 added native Trezor support for cold storage, while Nunchuk added BitBox02 Bluetooth connectivity. Additionally, RoboSats Alpha 0.87 added three new coordinators and encrypted image uploads through Noster Blossom servers.
A data breach at shipping provider ShipMonk exposed the personal details of 67,000 US-based Trezor customers. The breach revealed that ShipMonk violated its contract with Trezor by failing to delete customer records older than 90 days.