A16z Wants Your Crypto Private and Your Car Tracked by Flock
BNB Price Faces $750 Test After Sharp Rebound: Can Bulls Push Higher?
Crypto Liquidity Is Moving – Here’s Where the Money Is Going
Bitcoin ETFs Ended Three-Week Streak of Inflows with $463M in Outflows
Revolut Allegedly Leaks Personal Information of High-Net-Worth Users
Revolut Faces Allegations of User Data Leak Due to Fraudulent Requests
REVOLUT DISCLOSES DATA BREACH WITH PASSPORTS, STATEMENTS AND BITCOIN...
Huobi Founder Leon Li Sells London Mansion for £190M After Buying It for £139MAccording to the...
Nomic Double-Spend Leaves a Third of Osmosis Bitcoin Unbacked
Fed Rate Hike Odds Jump to 87% as FOMC Meeting Nears
Bloomberg: SemiAnalysis Acquires Citrini Research, Founder to Remain as CEO
A whale has spent 85.42M $USDC to buy 1,075.6 $BTC at an average price of $79,412 over the past 4...
ZachXBT: Revolut Suspected of Failing to Identify Fraudulent Request, Some Users' Personal Information Leaked
Mecka AI Nears Funding Round Led by Sequoia, Valuation Around $500M
Huobi Founder Li Lin Sells London Mansion for £190 Million
Bitcoin Investors Now Have the Full Picture Before the Fed’s Move: Here’s What It Says
Solana Price Prediction: Can SOL Reach $150 After the September 9 Upgrade While Pepeto Buyers Race the Stage Timer?
BlackRock's iShares Ethereum Trust Sees $149 Million in Inflows
Canada Regulator Clears Tokenized Deposits for Banking System
Robinhood CEO: Tokenized Stocks Do Not Need Company Approval if Underlying Share Rights Remain...
Bitdeer Maintains Zero Bitcoin Holdings, Sells 293.2 BTC This Week
How High Could XRP Go if Trump Gives Every American $5K? ChatGPT Sets Specific Targets
Metaplanet CEO surrenders $220 million in stock rights to rebuild trust with investors
Bitcoin Spot ETFs Experience Continued Net Outflows
Ethereum Spot ETFs See Significant Net Inflows
Bitcoin ETFs See $13.29M Net Outflows on September 11 (ET), Extending Outflow Streak to Four Days;...
Bitcoin ETFs Experience $13 Million Outflows as Ethereum ETFs Attract $216 Million
Bitcoin ETFs Extend Outflow Streak to Four Days on September 11 (ET), While Ethereum ETFs See $216M...
Why Crypto’s Next Adoption Test Is Operational, Not Speculative
Sydney Sweeney Takes Equity in Novig for Its Viral Ad
Huobi HTX Records Net Capital Inflow of Over $446M in 24H and $438M in 7 Days, Ranking First Among Mainstream CEXs
Total Value of Tokenized Assets Reaches $346 Billion Across 47 Asset Types
WSJ: Markets Start Pricing in a Series of Fed Rate HikesAccording to The Wall Street Journal, that...
Coinbase Wallet Introduces Pulse Mode for Enhanced Perpetual Futures Trading
Tesla Stock Is Becoming Elon Musk’s AI Empire
Trump sues JPMorgan for $5B! Ledger prepares for $4B IPO! “Crypto Adoption is no longer reversible” says PWC!
From Stellar to Canton: How Franklin Templeton Adopted Tokenization
Hyperliquid Burns Tokens Worth $2.65 Million in 24 Hours
Wealth Managers Signal Crypto Shift With 60% Planning Allocations
Pump fun(@Pumpfun) sold another 77,705 $SOL ($7.88M) 6 hours ago.In total, pump.fun has sold...
Surge in Tokenized ETF Deposits into DeFi Reaches $68 Million
BitMEX Co-Founder Ben Delo Donates Record £36 Million to Reform UKBitMEX co-founder Ben Delo has...
Independent Solo Miner Successfully Mined Block 966,351, Receiving 3.147 BTC
Why Nasdaq surveillance cannot settle the fight over 24/7 tokenized markets
157,173,943 $USDT (157,134,597 USD) transferred from unknown wallet to #Binance...
Robinhood Chain Reports Significant Revenue Decline Amid Increased Activity
BitMEX Co-founder Ben Delo Donates £36 Million to UK Reform Party, Setting Record for Single Political Donation
Circle Launches Euro Stablecoin EURC on South Korean Exchange Upbit
Clearpool Targets XRP Ledger Credit Market With Token Overhaul
Morgan Stanley MSBT ETF Boosts Holdings by 51.58 BTC Amid Significant Inflows
Symbiosis Bitcoin Bridge Suspends BTC Routing Following Security Incident
L-BTC resumes trading with reserves covering just 85% of supply
A Whale Bought Over 36,000 ZEC in Six Days, Worth Approximately $41.56 Million
193,344,000 $USDC (193,296,630 USD) transferred from Unknown Whale 1 to #Aave...
US House Committee to Review Crypto Tax Legislation on September 16
KLEA Crypto Daily: Friday, September 11, 2026
745 $BTC (57,550,174 USD) transferred from #Coinbase to unknown wallet...
Nvidia in Talks to Invest in Anthropic's IPO Project, Up to $10 Billion
Crypto Fear and Greed Index Index Value : 63 Sentiment : Greed BTC Price : $77209 ...
pointfarmcap FLIPS theunipcs FOR #1 ALL-TIME PNL ON fomo ...
US Bank moves USBDC across borders on Stellar, but only inside its own walls
Apollo Global Management Winds Down Certain Products at Eliant Trade Finance Platform
811 $BTC (62,580,323 USD) transferred from unknown wallet to #Coinbase...
Robinhood CEO says companies shouldn't get veto over stock tokens in AMC feud
CFTC Implements Automatic 30% Whistleblower Awards for Cases Under $5 Million
Solo Bitcoin Miner Hits $244K Jackpot After Nearly 40-Day Drought
193,344,315 $USDC (193,340,448 USD) transferred from #Aave to Unknown Whale 1...
Mecka AI Approaches $500 Million Valuation in Sequoia Capital Funding Round
UniCredit Explores Crypto Custody and Brokerage…
Trezor Users Got a “Critical Security Alert”…
Our third-party e-mail provider has been breached. Please be aware that the email named ‘Critical Security Alert: STM32 Entropy Vulnerability’ is not coming from us, and it’s a phishing attempt. Do not click on any link.
We have taken down the domain, and we are investigating the situation, including how the hackers got access to our legit domain.— Trezor (@Trezor) September 9, 2026
Why the STM32 Phishing Email Worked
The email was engineered to trigger the exact fear that makes a careful person act against their own interest. It claimed Trezor engineers had found a critical hardware vulnerability in the STM32 microcontrollers used in its devices, one that supposedly left recovery phrases with insufficient randomness, or entropy, on an estimated one in four devices. That framing is designed to make a holder rush to "fix" their wallet by entering their recovery phrase somewhere it can be stolen.The claim is false: Trezor confirmed there is no such defect, and its devices generate at least 128-bit entropy by default. The bait also leaned on genuine recent anxiety, following a Coldcard firmware flaw that FinanceFeeds reported was linked to more than $130 million in stolen Bitcoin earlier this year.The delivery is what let it past spam filters. Because the message travelled through Trezor's real newsletter infrastructure rather than a spoofed domain, it displayed help@trezor.io as the sender and passed the standard authentication checks, so services like Gmail treated it as legitimate. A holder checking the sender address, the first thing security guides tell them to do, would have seen nothing wrong.Investor Takeaway
The breach hit the email channel, not the wallets: Trezor's devices were not compromised and no keys were extracted, so a holder who did not act on the email has nothing to fix.
What Trezor Says Was and Was Not Exposed
Trezor's statements describe a compromise of its external email provider, which gave attackers a channel to send authenticated-looking phishing, rather than any access to its own systems or hardware. The company said it deactivated the malicious domain and is investigating how its official domain was used.No confirmed cryptocurrency losses have been tied to the campaign as of publication, and the STM32 vulnerability at the center of the email is fabricated. The one thing holders must not do is treat the email's authenticity, its real sender address and clean authentication, as evidence that its contents are true.The ShipMonk Breach Five Days Earlier, and the BitBox Signal
This is Trezor's second third-party exposure in about a month. On September 4, FinanceFeeds reported that a breach at Trezor's shipping provider ShipMonk had exposed the personal data of around 67,000 more customers, bringing the total near 80,000, with names, emails, phone numbers and addresses among the leaked records. That earlier leak matters here because it hands attackers exactly the contact details needed to make phishing feel personal, part of a wider run of third-party breaches hitting the sector that includes a Ledger customer-data exposure through its provider Global-e and a Pocket Bitcoin breach affecting more than 5,400 customers.The email attack may not be Trezor's alone. Swiss rival BitBox reported an almost identical phishing email reaching its own subscribers the same day and said its preliminary review found it "very likely that our newsletter provider got compromised," with several Bitcoin companies appearing to share the same platform.Casa co-founder Nick Neuman and the firm's chief security officer, the Bitcoin security researcher Jameson Lopp, both said on X that the messages did not resemble ordinary spoofing, with Neuman writing that "it's likely that a marketing email provider was compromised." That remains a hypothesis rather than a confirmed finding, but with two named executives and a second affected company describing the same shared-provider pattern, the exposure looks more like an industry-wide supply-chain problem than a single vendor's lapse.Our preliminary review of the phishing mail that was sent out to our newsletter subscribers about an hour ago found that it is very likely that our newsletter provider got compromised.
Multiple other Bitcoin companies got targeted as well, and it appears that we all share the same newsletter provider.We sent out a phishing warning to all our newsletter subscribers, contacted the provider and reported the phishing domains. Most of the phishing links appear to have been taken down already.We are still actively investigating this situation and will update you once we know more.— BitBox (@BitBoxSwiss) September 9, 2026
There are convincing phishing emails going out right now from hardware wallet companies (have heard Trezor and Bitbox at least). It's likely that a marketing email provider was compromised. That will mean more customer emails are leaked.Stay frosty and don't trust provider… pic.twitter.com/jHtdRE9S2A
— Nick Neuman (@Nneuman) September 9, 2026
What a Trezor Holder Should Do Now
The safe response is the boring one. Do not click any link in the STM32 email, do not enter your recovery phrase anywhere in response to it, and verify any genuine security notice through the official Trezor Suite application rather than an email link, which mirrors the guidance FinanceFeeds set out when mail-based phishing hit Ledger and Trezor owners earlier this year.A recovery phrase should never be typed into a website or app under any circumstances, because no legitimate firmware update or security fix requires it. If you received the email but did nothing, your wallet is unaffected. If you clicked through and entered your seed, move your funds to a new wallet with a newly generated recovery phrase immediately, and treat the old one as compromised.Investor Takeaway
The channel is the weak point, not the wallet: this breach and the ShipMonk leak both hit third-party vendors, so the lesson for holders is to distrust the delivery channel, since even a real sender address no longer guarantees a real message.
Source: FinanceFeeds