Bitcoin Price Surges Past $85K as Bulls Muscle Back Into the Fight
Arthur Hayes Predicts Ethereum Will Reach $10K by Year-End
Bloomberg Terminal Launches Stablecoin Dashboard, Function Code RWAS
Illinois Draft Rules Reveal Which Crypto Moves Trigger Its New Tax
Cardano tapped by Brazil’s state oil giant to track cleaner jet fuel and diesel
Bitcoin could react to new 40M barrel US oil sale before a single barrel is delivered
Bitcoin Surges Above $85,000 Following Cooling Inflation Data
Allium Launches Stablecoin Tracking Function on Bloomberg Terminals
Bonk Guy (@theunipcs) has now made over $1M on $SI!He invested $168K to buy 19M $SI, now worth...
U.S. Short-Term Interest Rate Futures Increase Amid Rate Hike Speculation
U.S. GDP Growth for Second Quarter Reaches 2.2%
U.S. Core PCE Price Index Shows Year-on-Year Increase of 3% in August
America’s economy grew at a 2.2% annual rate in the second quarter,...
Coinbase perpetual futures trading outside the US to pause for about 1 hour starting 17:00 on October 1
Trump Is Considering Former SEC Chair Jay Clayton for an AI Adviser Role
Alleged North Korean Bitget Hackers Shield $3.8M in Zcash’s Ironwood Pool, ZachXBT Says
CFTC Readies Action on Prediction Market Promos, Expected This Week
Traders increase bets on Fed rate hike
US core PCE annual rate comes in below expectations, hitting a six-month low
Polymarket Implements Responsible Gambling Features Amid Regulatory Scrutiny
Polymarket Adds New User Protections, Users Can Now Exclude Themselves From The Platform From 30...
Trump Announced “Super Intelligence” Era and Reached Agreement with Tech Giants on Four Levels of Oversight
Solv Says BTC+ Is Redeeming Normally After One Address Hit a Risk Review
US Private Sector Job Growth Tops ForecastsPrivate businesses in the US added 90K jobs in September...
US September ADP employment at 90,000, beating the expected 70,000
American private employers added 90,000 jobs in September, exceeding...
Aptos (APT) Price Prediction 2026, 2027 – 2030: Will APT Price Hit $30 by 2026?
SlowMist Revealed Details of the Attack on Bitget’s Hot Wallets
Michael Saylor Advocates for Collaboration Among Bitcoin Treasury Companies
FCA opens crypto authorization window ahead of 2027 UK regime
107,085,329 $USDC (107,098,126 USD) transferred from USDC Treasury to Unknown Whale...
Cardano Foundation and Petrobras Collaborate on Blockchain Fuel Applications
AMD vs. Intel: Which Stock Could Rise More From Here?
Coinbase just completed its US derivatives stack but its biggest bet still sits outside it
Crypto advocacy group Stand With Crypto rolls out its first round of Senate endorsements after
Morning Minute: Robinhood Adds Perps, Weekend Stocks, and AI Traders
Attackers in Bitget Exploit Begin Transferring Approximately 2,700 ZEC to Ironwood Shielded...
107,085,329 $USDC (107,096,145 USD) transferred from unknown wallet to USDC Treasury...
CFTC Investigates Former Congressman Adam Kinzinger Over Prediction Market Trades
Gram (prev. Toncoin) Price Prediction 2026, 2027 – 2030: Will TON Price Reach $10?
BetFury Futures: An x1000 Multiplier and Slippage-Free Crypto Trading
Saylor: Bitcoin treasury companies like Strategy and Strive can jointly drive the digital credit market
CFTC Investigating Adam Kinzinger Over Kalshi Bets on His Own Pardon: Report
Surge in Altcoin Exchange Deposits Signals Market Activity
Scorechain Expands Compliance Tools to Sui Network
UK Financial Conduct Authority Starts Accepting Crypto Authorization Applications
250,000,000 $USDC (250,027,875 USD) minted at USDC Treasury...
UPDATE: Bitget also said it has replenished its user protection fund to more than $300 million, two
Binance launches o1.exchange (O) Alpha trading competition with $200,000 prize pool
OpenAI, Google and four other companies sign White House voluntary AI safety agreement, committing to external audits
Binance Alpha Trading Competition: Trade o1.exchange (O) and Share $200K Worth of Rewards (2026-09-3...
Higgsfield at $5.4 Billion: What the AI Platform Can Do and How Much Video Generation Costs
A stronger dollar is a weaker threat to bitcoin than traders think
Robinhood Adds AI Trading Agents to Its Mobile App
222,784,422 $USDC (222,814,497 USD) transferred from USDC Treasury to unknown...
Franklin Templeton Highlights Asia's Leadership in Tokenized Finance
Altcoin exchange deposit count jumps 160% in 2 weeks
Evernorth XRP Treasury Deal: What the Nasdaq Listing Could Mean for XRP Holdings
Illinois Drafts Rules To Tax Crypto Transactions Starting 2027
SEC plans to update transfer agent rules, focusing on on-chain share registration and avoiding a "new paper crisis"
SEC’s Paul Atkins Says Tokenization Rules Will Move Ahead Despite CLARITY Act Failure
Bitget Protection Fund Back Above $300M After $387.5M Hack, P2P Withdrawals Return October 2
120,000,000 $USDC (120,016,319 USD) transferred from unknown wallet to #Aave...
European Commission Reviews MiCA Regulations Amid Compliance Concerns
McDonald's AI ‘Pricing Engine’ Gauges What Customers Will Pay for a Big Mac: Report
A single market worth protecting: Getting the MiCA review right
Apple Pay officially launches in India, Axis Bank credit card users first to gain support
Bitget hackers move $4 million into Zcash’s private pool, making funds harder to trace
The SEC Is finally modernizing transfer-agent rules. Wall Street must not repeat the ‘paperwork crisis’
Your crypto hardware wallet can stay secure while everything around it fails
Two wallet incidents this week exposed a growing weakness in crypto self-custody: the systems surrounding hardware devices.
D’CENT, a popular hardware wallet in South Korea, said it is investigating unauthorized transfers from some users of its software-based App Wallet, while Trezor, another crypto hardware firm, disclosed that attackers exported 347,149 customer email contacts after breaching third-party marketing provider Brevo.
Neither company has reported a compromise of its hardware-wallet security.
Yet both incidents created routes to the same prize: the recovery phrase that can reconstruct a wallet and control its assets.

D’CENT phrase reuse pulls hardware assets into software risk
D’CENT’s investigation shows how moving a recovery phrase into software can extend risk beyond the device where the wallet was originally created.
The company first received reports of unauthorized transfers on Sept. 16 and found that most affected users were operating its App Wallet, which stores or imports keys on a phone. D’CENT has not confirmed a compromise affecting its hardware products and continues to investigate the cause and total scope of the transfers.
Its current criteria focus on wallets whose recovery phrases were entered into the App Wallet and that had transaction-signing history on versions earlier than 8.1.0, released Nov. 5, 2025. The potential exposure spans Bitcoin, Ethereum, XRP Ledger, Tron, and other EVM-compatible networks.
That creates a potential crossover for hardware users. A recovery phrase generated on a D’CENT device can reconstruct the same private keys elsewhere if the user later imports those words into the software wallet. D’CENT said connecting a hardware device to its app normally does not transfer the recovery phrase onto the phone; manually importing the phrase into App Wallet does.
The company is advising users who meet its criteria to update the app before signing another transaction, create a wallet backed by a new recovery phrase, and transfer affected assets rather than restoring the old phrase onto another device.
D’CENT is also working with exchanges, law enforcement and blockchain investigators to trace and potentially freeze stolen assets.
Trezor breach turns customer data into an attack surface
Trezor’s incident began further from the wallet itself, showing how information about who owns a device can become useful infrastructure for attackers.
Brevo said an attacker exploited a flaw in its SAML single-sign-on implementation to reach 138 customer accounts. Contacts were exported from 43 accounts, while six were used to send phishing emails through legitimate customer infrastructure. The messages therefore passed normal email-authentication checks and appeared to originate from trusted systems.
For Trezor, the breach exposed 347,149 marketing email contacts. Attackers sent a message claiming a critical hardware vulnerability and requiring customers to download an application that then requested their wallet backup. About 2,500 recipients reached the malicious domain before Trezor disabled it.
Trezor said clicking the link alone did not expose funds. However, the risk arose if a user entered the backup into the malicious application, allowing an attacker to recreate the wallet elsewhere.
The exported email list creates a longer-lived problem even after the first phishing domain has disappeared. Verified contact details for hardware-wallet users can be reused in follow-up campaigns tailored around future security alerts, software updates, or support requests.
Trezor had already confronted a related exposure in August when a shipping-provider incident disclosed customer identity and order information. The company said that breach exposed phone numbers and shipping addresses while leaving its wallets unaffected.
The two events show how vendors outside a hardware maker’s direct infrastructure can supply attackers with information needed to identify likely crypto holders and build more convincing approaches.
Wallet makers face a wider security burden
The incidents are likely to increase pressure on wallet companies to treat customer databases and software workflows as part of the same security program as their devices.
Trezor said it has suspended its Brevo account and is reviewing vendor relationships and security requirements following the breach. Brevo closed the SSO route used by the attacker, reset active sessions, and said it was deploying a permanent fix that restricts authentication to the organization that owns each SSO configuration.
D’CENT, meanwhile, said it is adding safeguards and pre-release verification procedures while its investigation continues. Its immediate challenge is determining the full set of affected addresses and whether assets already moved can be recovered through exchanges or law enforcement.
Both companies still depend on users keeping recovery phrases offline. Once those words are entered into compromised software or surrendered through phishing, the attacker no longer needs to defeat the hardware device.
That shifts part of the competitive burden for wallet makers beyond secure chips and signing architecture.
Companies selling self-custody products will increasingly have to show how they limit retained customer data, vet outside vendors, and design companion software so a compromise elsewhere in the stack doesn't provide another path to the keys their hardware was built to protect.
Source: CryptoSlate