GetChain News
中简 中繁 EN
GetChain News
Toggle sidebar

Regulation/Compliance

News linked to both this project and an event.

The EU Cyber Resilience Act officially takes effect, requiring crypto wallet vendors to report vulnerabilities within 24 hours.

According to Cointelegraph, the EU Cyber Resilience Act (CRA) officially entered into force, requiring cryptocurrency hardware and software wallet providers to submit an early warning within 24 hours of discovering a serious security vulnerability or an actively exploited vulnerability, a complete notification within 72 hours, and a final report within 14 days after remediation measures are implemented. The regulation applies to all "products with digital elements" sold in the EU market. Violating companies face administrative fines of up to €15 million (approximately $17.3 million) or 2.5% of their global annual turnover, whichever is higher; providing false or misleading information will result in an additional fine of up to €5 million. Previously, Trezor and BitBox have both disclosed user data breach incidents and warned users to be vigilant against phishing emails disguised as security notifications.

Trezor Third-Party Email Service Provider Compromised, Phishing Emails Impersonate Official Communications

The official X account of Trezor (@Trezor) announced that its third-party email service provider was compromised by hackers, with a phishing email titled "Critical Security Alert: STM32 Entropy Vulnerability" circulating. Trezor explicitly clarified that the message was not sent by the company, and has urgently taken down the associated domains while launching an investigation. In recent days, Trezor had already suffered a customer data breach, resulting in the theft of the names, home addresses, and email addresses of approximately 67,000 users. Trezor advised users to avoid clicking any suspicious links and strictly refrain from disclosing their wallet mnemonics to anyone.

Trezor's Third-Party Email Service Provider Breached; Users Warned of "Critical Security Alert" Phishing Emails

Odaily News: Trezor stated that its third-party email service provider has been breached and is currently under investigation. It warns users not to click on links in fraudulent "Critical Security Alert" phishing emails. (Cointelegraph)

Independent verification scope expanded, Sparrow Wallet releases v2.5.4 security update

Odaily News: Sparrow Wallet v2.5.4 has been released following an extensive AI-assisted review, featuring multiple security hardening updates aimed at reducing users' reliance on external servers such as Electrum.Additionally, this version strengthens Ledger, Keycard, Trezor, Payjoin, PSBT, and multi-signature handling, removes Bitcoin Core credentials and other sensitive information from debug logs, restricts permissions for existing wallet and backup directories to owner-only access, closes residual local DNS resolution leaks when using Tor, and reinforces validation for wallet import, signing, downloads, and server responses. The update expands Sparrow Wallet's scope of independent verification for transaction data, hardware devices, and other inputs, reducing dependence on data provided by external servers. (Bitcoin News)

Coldcard incident boosts BitBox credit card sales by ~10x, while Trezor and OneKey see rising demand

Odaily News - Hardware wallet maker BitBox reports that credit card sales in August grew roughly 10x compared to the baseline of previous weeks, with the increase primarily driven by North America. Trezor and OneKey also confirmed rising sales during the same period, though neither disclosed specific figures.Trezor, BitBox, and OneKey have all re-reviewed their seed phrase generation, random number generator, entropy, and firmware verification processes. Trezor plans to conduct penetration testing on core firmware functions and publish related security audit reports. OneKey will strengthen reviews of security-critical code paths and transaction signing processes.Ledger CTO Charles Guillemet stated that AI-assisted attacks mean patch releases, vulnerability disclosures, and user education need to accelerate. Blockstream Jade has released a firmware update containing multiple fixes and recommends users simultaneously update their apps, operating systems, devices, routers, and home appliances. (Bitcoin.com News)

Rapid7 discloses crypto phishing campaign targeting 885,000 phone numbers and involving 5,576 Binance accounts

Odaily News Rapid7, a cybersecurity firm, has disclosed a crypto phishing campaign named Operation Asterix that targets approximately 885,000 phone numbers across multiple countries, redirecting victims to fraudulent wallet service websites. A total of 5,576 phone numbers have been matched with Binance user accounts and placed on the attack queue.The attackers steal seed phrases through fake apps impersonating Ledger, Trezor, and Exodus, while also contacting victims via fraudulent customer support emails and phone calls. Rapid7 also found that among over 316,000 phone numbers in Germany, 43,066 were matched with crypto trading accounts, representing a hit rate of approximately 13.6%.The related attacks also include a bulk phone number verification tool targeting Kraken accounts, and the investigation revealed that AI tools are being widely used in phishing operations. According to data from blockchain security firm Hacken, phishing attacks and social engineering scams caused $306 million in losses in the first quarter of this year, accounting for the majority of the $482 million total losses in the crypto industry. (Cointelegraph)

Crypto Companies Send Joint Letter to AI Labs, Urging Access to Frontier Models for Bitcoin Developers

据 Cointelegraph 报道,比特币政策研究所(BPI)联合 Anchorage Digital、BitGo、Bitwise、Blockstream、Kraken、Ledger、MARA、Trezor 等多家加密机构,发布公开信敦促各大前沿 AI 实验室为比特币及开源软件开发者建立或扩展可信访问计划。 信中指出,Bitcoin Core 等开源维护者目前缺乏对 AI 实验室网络安全程序的访问渠道,被迫依赖能力较弱的开源模型,而比特币网络当前保护着逾 1 万亿美元资产,任何开源基础设施漏洞均可能危及用户毕生积蓄。BPI 同时披露,已收到多份报告显示包括潜在境外势力在内的复杂攻击者正借助先进 AI 能力持续发动攻击。

Trezor: Approximately 10% of Global Crypto Users Self-Custody Their Private Keys

hardware wallet company Trezor stated there is a distinction between Bitcoin self-custody and holding Bitcoin credit exposure. When users store assets on exchanges, brokerages, or funds, they are actually relying on third-party ledger records and withdrawal arrangements. The company noted that after the full implementation of new EU crypto regulations, some exchanges that failed to obtain licenses in time have stopped offering regulated services to EU users. Trezor stated that its founders Marek Palatinus and Pavol Rusnák launched the first hardware wallet 12 years ago, moving private keys from internet-connected computers to dedicated devices. Trezor explained that private keys are generated on the device and never leave it, with transactions being signed inside the device before being sent. Trezor CCO Danny Sanders previously stated that if users put Bitcoin into ETFs and call it Bitcoin ownership, it would be one of the worst outcomes for the industry. Trezor estimates that among approximately 600 million global crypto users, about 10% self-custody their private keys, and around 12 to 13 million people use hardware wallets.

Data: Coinbase and Kraken Account for 22% of AI Mentions in the U.S. Crypto Industry

According to PRNewswire, market analysis reports indicate that Coinbase and Kraken together account for 22% of all AI mentions across the cryptocurrency category—Coinbase accounts for 13%, and Kraken for 9%—holding a lead over other U.S. trading platforms by more than threefold. Gemini ranks third with 5.5%, Robinhood Crypto fourth with 5%, and BlackRock’s spot Bitcoin exchange-traded fund (ETF), IBIT, fifth with 4.5%, dominating queries related to “Bitcoin ETFs.” Additionally, hardware wallets are losing influence in AI responses: while Ledger and Trezor still dominate queries related to “cryptocurrency wallets,” AI increasingly recommends custodial solutions offered by regulated trading platforms when addressing questions about the “best way to store cryptocurrency assets.” (Note: “AI mentions” refers to how frequently an AI chatbot references a particular brand, product, or company when responding to user queries.)