Citigroup Projects TSMC Revenue Growth to Exceed 40% Through 2027
BitGo and HashKey Cloud Enhance Partnership for Institutional Services in Asia-Pacific
Nvidia Stock Price Today: SpaceX Seeks $40 Billion In Debt To Buy Nvidia AI Chips
Hunter Biden LAPTOP Coin Surges 21% After Crash Forensic Report
Binance Will Support Scheduled Upgrade for Stock Trading Services - 2026-10-10U.S. Stock Trading on ...
Bitcoin whales dormant for years are waking up.Another #Bitcoin whale, bc1q4h, transferred 4,500...
$PONS listed on Bithumb spot・
Bithumb to list PONS token on KRW market
TOKEN2049 Expands to the US With a New York Edition in June 2027
Standard Chartered's Singapore unit plans to offer custody for selected crypto assets,
Ethereum OG pinosaur.eth, who bought ETH at a cost as low as $50, unstaked all 9,618 $ETH ($24.58M)...
New York Jury Convicts Uranium Finance Hacker, Facing Up to 20 Years in Prison
UPBIT Launches PONS Trading with Multiple Currency Support
Samsung Wallet to Introduce USDC Stablecoin Feature in October
Hyperliquid CEO Defines Protocol as Infrastructure, Not an Exchange
Samsung Wallet to Integrate USDC on Sui Blockchain by Late October
Upbit to list PONS token on KRW, BTC, and USDT markets
Address Transfers 100.02 BTC Worth $8.55 Million After 16 Years of Dormancy
$PONS listed on Upbit spot (KRW)・
Peter Brandt Favors Monero Over XRP Despite Bullish Price Targets
Standard Chartered Expands Digital Asset Custody Services in Singapore
Justin Drake Advocates for Migration to New Crypto Addresses Amid Security Concerns
@wublockchain12 据 Sui Foundation 官方公告,三星电子旗下 Samsung Wallet 已选择 Sui 作为区块链基础设施合作伙伴,计划通过 Sui 网络向美国约...
Bithumb to List AIA and CASHCAT Tokens on KRW Market
$AIA, $CASHCAT listed on Bithumb spot・
Binance Executive Highlights Demand for Tokenized Stocks Amid Information Flow Challenges
1,201 $BTC (100,052,162 USD) transferred from unknown wallet to Coinbase...
Hyperliquid Strategies DAT CEO Confirms They Are The Not The Buyers Of The $320M OTC Sale By...
Important News from Last Night and This Morning (October 7–October 8)
Samsung Electronics Q3 operating profit surges nearly 8x, hitting record high for fourth consecutive quarter
1,645 $BTC (136,985,125 USD) transferred from unknown wallet to Coinbase...
Franklin Templeton CEO Critiques Competitors at TOKEN2049 Singapore
HyperLabs unstaked 3.75M $HYPE ($331.4M) 9 hours ago to distribute to the team members and will...
614 $BTC (51,115,586 USD) transferred from Coinbase Institutional to unknown new...
Crypto News Site CoinTelegraph Said To Be Looking For A Buyer After Google Cuts Its Web Traffic By...
Whale pinosaur.eth liquidates ETH held for 9 years, netting $24.21 million profit, a 65x return
Robinhood Puts $25M Into Bitcoin, Citing Belief in Crypto’s Future
614 $BTC (51,160,178 USD) transferred from Coinbase Institutional to unknown new...
FDUSD Issuer First Digital to Go Public on Nasdaq in $250 Million SPAC Deal
Cathie Wood's Ark Invest sold 151,903 shares of Robinhood, worth $16.6 million, from its
Cointelegraph Seeks Buyer as Traffic Plunges From 12 Million to 700,000 VisitsCointelegraph, one of...
133,797,000 $USDC (133,796,531 USD) transferred from Unknown Whale 1 to #Aave...
Hong Kong Government Addresses Regulation of Emerging Payment Platforms
US SOL Spot ETF Sees Single-Day Net Outflow of $4.8001 Million
SlowMist's Cos: Beware of bookmark phishing attacks targeting the FOMO web platform
Samsung Wallet and Samsung Pay will support USDC transfers on Solana for cross-border
The U.S. government continues to move funds, transferring another $566M over the past 10 hours,...
A wallet withdrew 1,000 ZEC worth $1.33 million from Binance, then moved them into a privacy pool
US ZEC Spot ETF Sees Single-Day Net Outflow of $8.4879 Million
Cointelegraph Seeks Buyer as Traffic Plunges From 12 Million to 700K VisitsCointelegraph, one of...
Hashi Mainnet to Launch With $500M in Capital Backing, Adds Anchorage Digital to Coalition
US government moves $470 million in seized crypto to Coinbase wallets, raising Bitcoin sale questions
614 $BTC (51,147,271 USD) transferred from Coinbase Institutional to unknown new...
Vitalik Buterin said industry should take risks to cryptography from
2,050 $BTC (170,834,648 USD) transferred from unknown wallet to Coinbase...
Sources: Cointelegraph is looking for a buyer
Korean Won Represents 25% of Global Fiat Cryptocurrency Trading Volume
XRP Whale Transfers off Binance Reach Highest Level in 7 Months
Cointelegraph Seeks Buyer Following Significant Traffic Decline
Hyperliquid dev team redeems 3.75M HYPE worth $332M, part of it re-staked
Crypto news site Cointelegraph seeks buyer after web traffic plunges
840 $BTC (69,981,981 USD) transferred from unknown wallet to Coinbase Institutional...
Dow Falls Nearly 300 Points As Bond Selloff Pushes 30-Year Yield To 5.73%
Sui Integrating with Samsung Wallet, 82 Million Galaxy Devices in the US to Support USDC Transfers
Bitmine Plans to Halt ETH Purchases Upon Reaching 5% Circulating Supply
Wells Fargo Negotiates with Kraken's Parent Company for Crypto Liquidity
Vitalik Buterin Warns AI Could Undermine Cryptography Within Two YearsEthereum co-founder Vitalik...
973 $BTC (81,197,515 USD) transferred from unknown wallet to Coinbase Institutional...
Robotics data startup Mecka AI completes $60 million Series B round led by Sequoia Capital
Trezor Users Got a “Critical Security Alert”…
Our third-party e-mail provider has been breached. Please be aware that the email named ‘Critical Security Alert: STM32 Entropy Vulnerability’ is not coming from us, and it’s a phishing attempt. Do not click on any link.
We have taken down the domain, and we are investigating the situation, including how the hackers got access to our legit domain.— Trezor (@Trezor) September 9, 2026
Why the STM32 Phishing Email Worked
The email was engineered to trigger the exact fear that makes a careful person act against their own interest. It claimed Trezor engineers had found a critical hardware vulnerability in the STM32 microcontrollers used in its devices, one that supposedly left recovery phrases with insufficient randomness, or entropy, on an estimated one in four devices. That framing is designed to make a holder rush to "fix" their wallet by entering their recovery phrase somewhere it can be stolen.The claim is false: Trezor confirmed there is no such defect, and its devices generate at least 128-bit entropy by default. The bait also leaned on genuine recent anxiety, following a Coldcard firmware flaw that FinanceFeeds reported was linked to more than $130 million in stolen Bitcoin earlier this year.The delivery is what let it past spam filters. Because the message travelled through Trezor's real newsletter infrastructure rather than a spoofed domain, it displayed help@trezor.io as the sender and passed the standard authentication checks, so services like Gmail treated it as legitimate. A holder checking the sender address, the first thing security guides tell them to do, would have seen nothing wrong.Investor Takeaway
The breach hit the email channel, not the wallets: Trezor's devices were not compromised and no keys were extracted, so a holder who did not act on the email has nothing to fix.
What Trezor Says Was and Was Not Exposed
Trezor's statements describe a compromise of its external email provider, which gave attackers a channel to send authenticated-looking phishing, rather than any access to its own systems or hardware. The company said it deactivated the malicious domain and is investigating how its official domain was used.No confirmed cryptocurrency losses have been tied to the campaign as of publication, and the STM32 vulnerability at the center of the email is fabricated. The one thing holders must not do is treat the email's authenticity, its real sender address and clean authentication, as evidence that its contents are true.The ShipMonk Breach Five Days Earlier, and the BitBox Signal
This is Trezor's second third-party exposure in about a month. On September 4, FinanceFeeds reported that a breach at Trezor's shipping provider ShipMonk had exposed the personal data of around 67,000 more customers, bringing the total near 80,000, with names, emails, phone numbers and addresses among the leaked records. That earlier leak matters here because it hands attackers exactly the contact details needed to make phishing feel personal, part of a wider run of third-party breaches hitting the sector that includes a Ledger customer-data exposure through its provider Global-e and a Pocket Bitcoin breach affecting more than 5,400 customers.The email attack may not be Trezor's alone. Swiss rival BitBox reported an almost identical phishing email reaching its own subscribers the same day and said its preliminary review found it "very likely that our newsletter provider got compromised," with several Bitcoin companies appearing to share the same platform.Casa co-founder Nick Neuman and the firm's chief security officer, the Bitcoin security researcher Jameson Lopp, both said on X that the messages did not resemble ordinary spoofing, with Neuman writing that "it's likely that a marketing email provider was compromised." That remains a hypothesis rather than a confirmed finding, but with two named executives and a second affected company describing the same shared-provider pattern, the exposure looks more like an industry-wide supply-chain problem than a single vendor's lapse.Our preliminary review of the phishing mail that was sent out to our newsletter subscribers about an hour ago found that it is very likely that our newsletter provider got compromised.
Multiple other Bitcoin companies got targeted as well, and it appears that we all share the same newsletter provider.We sent out a phishing warning to all our newsletter subscribers, contacted the provider and reported the phishing domains. Most of the phishing links appear to have been taken down already.We are still actively investigating this situation and will update you once we know more.— BitBox (@BitBoxSwiss) September 9, 2026
There are convincing phishing emails going out right now from hardware wallet companies (have heard Trezor and Bitbox at least). It's likely that a marketing email provider was compromised. That will mean more customer emails are leaked.Stay frosty and don't trust provider… pic.twitter.com/jHtdRE9S2A
— Nick Neuman (@Nneuman) September 9, 2026
What a Trezor Holder Should Do Now
The safe response is the boring one. Do not click any link in the STM32 email, do not enter your recovery phrase anywhere in response to it, and verify any genuine security notice through the official Trezor Suite application rather than an email link, which mirrors the guidance FinanceFeeds set out when mail-based phishing hit Ledger and Trezor owners earlier this year.A recovery phrase should never be typed into a website or app under any circumstances, because no legitimate firmware update or security fix requires it. If you received the email but did nothing, your wallet is unaffected. If you clicked through and entered your seed, move your funds to a new wallet with a newly generated recovery phrase immediately, and treat the old one as compromised.Investor Takeaway
The channel is the weak point, not the wallet: this breach and the ShipMonk leak both hit third-party vendors, so the lesson for holders is to distrust the delivery channel, since even a real sender address no longer guarantees a real message.
Source: FinanceFeeds