Your signal. Your price.
Non-custodial payment processor Swiss Bitcoin Pay temporarily shut down its servers following a data breach that leaked customer emails, Bitcoin addresses, and IBANs. This event follows recent security breaches at both Revolut and hardware wallet manufacturer Trezor.
Attackers breached email marketing service Bravo to send highly convincing phishing emails to Trezor and BitBox users. By exploiting valid API keys, the phishes successfully bypassed standard SPF and DKIM email authentication checks.
Trezor and BitBox warned users of phishing emails sent via compromised third-party newsletter services. The fraudulent security alerts falsely claimed devices suffered from an entropy vulnerability.
Ledger CTO Charles Gilmette argues that artificial intelligence has simplified bug discovery, prompting some researchers to publish vulnerabilities prematurely to gain attention. Gilmette and Trezor security head Jan Komarek advocate for a standard 90-day private disclosure window to develop patches.
Trezor's shipping partner, ShipMonk, leaked customer records of approximately 67,000 US customers, bringing the total exposed to 80,000. The leak included names, physical addresses, phone numbers, and email addresses, highlighting shipping data risks.
Cake Wallet 6.4.4 added native Trezor support for cold storage, while Nunchuk added BitBox02 Bluetooth connectivity. Additionally, RoboSats Alpha 0.87 added three new coordinators and encrypted image uploads through Noster Blossom servers.
A data breach at shipping provider ShipMonk exposed the personal details of 67,000 US-based Trezor customers. The breach revealed that ShipMonk violated its contract with Trezor by failing to delete customer records older than 90 days.
A data breach at a Trezor logistics provider exposed over 13,000 customer records, including physical shipping addresses. Q advises purchasing hardware wallets using PO boxes, business addresses, and paying with cryptocurrency to prevent physical attack risks from shipping leaks.
Cold Card's proprietary library received minimal developer oversight compared to Trezor's highly audited, pure open-source alternatives. FOSS advocates argue that restrictive licensing structures limit the pool of competent code reviewers, shifting the entire audit burden onto the firm.
Seth announces that Cake Wallet has integrated native support for the Trezor Safe 7 hardware wallet. This update allows users to manage their Monero holdings securely via Bluetooth on iOS and Android devices.
BitBox patched severe firmware vulnerabilities on its multi-edition devices that risked arbitrary code execution and ransom address locking. This follows third-party data breaches at Trezor and SafePal, exposing details of 13,000 and 40,000 customers respectively without compromising private keys.
To prevent reliance on black-box chips, Zach Herbert explains Passport combines an internal avalanche noise source with multiple external entropy inputs. Thomas Susanka notes the Trezor Safe 7 mixes four separate entropy sources, including secure elements and the host computer.
Thomas Susanka addresses the August 10, 2024 security breach at a third-party fulfillment partner that exposed Trezor customer data. To limit data exposure, Trezor enforces a strict 90-day data retention policy with its shipping partners.
Thomas Susanka reveals Trezor plans to launch anonymous delivery to physical drop boxes in Europe by late September 2024, followed by a US launch. This initiative aims to remove physical home addresses from the distribution pipeline.
A third party shipping partner leaked sensitive data from over eleven thousand Trezor customers. Max advises purchasing hardware wallets in person at conferences using cash or Lightning to prevent home address leaks.
A third-party shipping provider for Trezor suffered a data breach exposing sensitive order data for customers. Simon Dixon notes this breach specifically compromised delivery addresses for orders placed in key international markets within 90 days prior to August 8, 2026.
Trezor shipping provider ShipMonk suffered a data breach exposing the personal information of 13,689 customers who ordered between May 10 and August 8. Trezor systems were unaffected, and their 90-day data deletion policy restricted the leak's scope.
Foundation forked Cold Card and Trezor code for its hardware wallet. Keon claims this action motivated Coinkite to shift to a restrictive license and modify its codebase, which ultimately introduced the critical vulnerability.
Danny Knowles confirms that Trezor and Foundation devices are safe because they do not use the same compromised library as Coldcard, indicating a specific, not widespread, self-custody vulnerability.