News linked to both this project and an event.
Odaily News: A vulnerability in email platform Brevo's login system allowed attackers to access 138 customer accounts and send phishing emails to approximately 347,000 Trezor newsletter subscribers. Accounts belonging to BitBox and cryptocurrency portfolio and tax reporting platform CoinTracking were also used to send similar scam emails.Trezor stated that the phishing email was titled "Critical Security Alert: STM32 Entropy Vulnerability," with links pointing to an app that asked users to submit their wallet backups. Trezor disabled the relevant domain via DNS within 20 minutes, but approximately 2,500 people had visited the link, and the company has alerted all 347,000 subscribers to the risk.Brevo stated that attackers exploited a failure in single sign-on configuration permission boundaries to access all organizations reachable by invited users. Six accounts were used to send phishing emails, and contact data from 43 accounts was exported. BitBox and CoinTracking said they have found no evidence of leaked company credentials, funds, or recovery phrases, but are treating the affected email addresses as potentially compromised. (Cointelegraph)
Odaily News: According to Bitcoin News monitoring, DART stated that it and independent white-hat researchers have recovered over 50 BTC from wallets affected by the COLDCARD entropy vulnerability, completing the transfer before malicious attackers could steal the funds. DART is a digital asset recovery organization that works with white-hat researchers to protect vulnerable funds and coordinate their lawful return to owners. The white-hat researchers did not request a bounty and will return the Bitcoin to its owners.The rescued BTC has been transferred to the Crypto Recovery Trust. This trust is a dedicated statutory trust established under Wyoming state law to hold recovered digital assets and return them after confirming and verifying the legitimate owners. The trust will document the recovery process, separate the BTC from DART and researchers' funds, conduct blockchain analysis, ownership verification, and sanctions screening, and provide a lawful return process for verified owners. If ownership is disputed, or if the relevant funds involve sanctions or criminal proceedings, the BTC will be handled in accordance with applicable legal procedures. DART stated that other vulnerable assets and recovery leads are still under review.
The official X account of Trezor (@Trezor) announced that its third-party email service provider was compromised by hackers, with a phishing email titled "Critical Security Alert: STM32 Entropy Vulnerability" circulating. Trezor explicitly clarified that the message was not sent by the company, and has urgently taken down the associated domains while launching an investigation. In recent days, Trezor had already suffered a customer data breach, resulting in the theft of the names, home addresses, and email addresses of approximately 67,000 users. Trezor advised users to avoid clicking any suspicious links and strictly refrain from disclosing their wallet mnemonics to anyone.
Odaily Planet Daily Report: Bitcoin hardware wallet manufacturer Coinkite disclosed in late July 2026 that a firmware build error introduced in March 2021 caused some Coldcard wallets to generate mnemonics from a smaller range, reducing the randomness of user private keys. Galaxy Research analysts stated that the Coldcard exploit occurred in multiple rounds, with observed Bitcoin losses rising from approximately $88 million to nearly $114 million within days. Researchers warned that other vulnerable addresses could still become targets, prompting many Coldcard users to move their Bitcoin. Coldcard is a Bitcoin-only wallet that supports offline signing via microSD card and optional QR codes. Launched in 2017, it has long been regarded as one of the security-focused Bitcoin hardware wallets.