Trezor2026-09-28 14:32:00Bitcoin Magazine Review Says Trezor Safe 7 Sits Between Open-Source Self-Custody and Mainstream Hardware DesignBitcoin Magazine has published an extensive review of the Trezor Safe 7, describing the device as a middle-ground option between fully open-source, self-custody-first hardware wallets and more consumer-oriented products built around polished design and user guardrails. The review highlights the wallet’s metal body, large edge-to-edge screen, tactile approval flow, and dual firmware approach, with separate multi-coin and Bitcoin-only stacks that users can switch between regardless of the device color they bought. A major focus of the piece is Trezor’s use of 20-word SLIP-39 backups and the company’s Shamir backup system. According to the review, the extra words do not increase entropy beyond the 128 bits users would expect from a 12-word seed, but they enable migration from a single-seed setup to Shamir shares without moving funds on-chain. The article also covers Safe 7’s Bluetooth support, Qi2 wireless charging, LiFePO₄ battery choice, and the security trade-offs that come with moving away from a stricter air-gapped model. The review further examines Safe 7’s four entropy sources, the absence of direct user-supplied entropy at wallet creation, and Trezor’s comments on why that design remains under discussion. It also points to the recent ShipMonk data breach affecting 67,000 U.S. customer records and notes Trezor’s plan to roll out an anonymous delivery option in the EU within weeks, followed by the U.S. soon after.280
Coldcard2026-09-20 05:41:35Coldcard firmware flaw from 2021 linked to more than $100 million in stolen BitcoinA 2021 firmware flaw in hardware wallet maker Coldcard has been tied to a large Bitcoin theft, according to the report cited by Odaily. The issue allegedly reduced randomness in some recovery seeds, and attackers have moved roughly 1,600 to 1,800 BTC from affected wallets since July 30, spanning thousands of addresses and valued at more than $100 million. Coinkite, the company behind Coldcard, said it has to consider the possibility that someone used AI to review its public firmware, though there is still no confirmation that AI played a role in the attack. The report also pointed to a separate disclosure from Shielded Labs researcher Taylor Hornby, who said an audit agent powered by Claude Opus 4.8 found a vulnerability in the Zcash Orchard shielded pool circuit dating back to 2022. In testing, the flaw could create unlimited counterfeit ZEC without leaving traces. Developers fixed the issue within days, and no theft has been confirmed. Separately, Chainalysis said daily on-chain inscriptions carrying malware instructions and command-and-control information rose from about 2.06 to 11.1, a 440% increase.340
Coldcard2026-09-20 05:41:52Coldcard firmware flaw tied to theft of roughly 1,600 to 1,800 BTC, report saysA 2021 firmware flaw in hardware wallet maker Coldcard left some recovery seeds with insufficient randomness, and attackers have drained roughly 1,600 to 1,800 Bitcoin from affected wallets since July 30, according to ChainCatcher. The stolen funds span thousands of addresses and are valued at more than $100 million. Coldcard manufacturer Coinkite said it must assume someone used AI to review its public firmware, though there is still no confirmation that AI was involved in the attack itself. The report also cited a separate finding from Shielded Labs researcher Taylor Hornby, who used a Claude Opus 4.8 auditing agent to identify a Zcash Orchard shielded pool circuit flaw dating back to 2022. In testing, the bug could generate unlimited counterfeit ZEC without leaving traces. Developers fixed that issue within days, and no theft has been confirmed. Chainalysis data in the same report showed that on-chain insertions carrying malware instructions and command-and-control information rose from about 2.06 per day to 11.1 per day, a 440% increase.360
BitBox2026-09-15 20:16:55BitBox adds Lightning hot wallet creation to its mobile BitBoxAppSwiss bitcoin hardware wallet maker BitBox said users of any BitBox hardware wallet can now create a Lightning Network hot wallet inside the mobile BitBoxApp. The setup lets users fund the wallet directly from on-chain balances and pay Lightning invoices without moving between different apps, wallets, or third-party services. According to the announcement, the Lightning wallet is derived from an existing BitBox backup, so users do not need to write down a new seed phrase, while the hardware wallet and the Lightning wallet remain separate. BitBox said the Lightning side operates as a hot wallet for small, everyday payments such as coffee purchases, invoices, and quick transfers, while long-term savings remain stored on the hardware device. Inside BitBoxApp, users can scan and pay Lightning invoices, send and receive bitcoin, claim a dedicated Lightning address, top up from an on-chain wallet, and move funds back again. The feature is built with Breez SDK and makes BitBox one of more than 100 integration partners in the Breez network. Spark provides the underlying infrastructure, and users do not need to run a node, open channels, or manage liquidity, with custody of funds remaining in users’ hands. Breez also launched the developer app Glow in August.600
Bitcoin2026-09-11 15:09:00Proof-of-concept runs SeedSigner on the $40 R36S handheldBitcoin News said in a post on X that a proof-of-concept built by @DesobedienteTec has successfully run SeedSigner on the R36S handheld game console, turning the device into a stateless Bitcoin transaction signer. The post described the setup as a way to use low-cost consumer hardware for Bitcoin signing rather than a purpose-built device. According to the same post, the R36S sells for about $40, does not include a wireless chip, and comes with two MicroSD card slots. Bitcoin News also noted that the handheld can emulate Nintendo, SEGA, PSP, and PS1 games. No other technical details were disclosed in the source provided.790
Trezor2026-09-10 21:28:55Trezor says breach at email marketing provider led to phishing emails sent to 347,000 customersTrezor said a breach at Brevo, the third-party marketing platform it uses for newsletters, allowed an unauthorized actor to send phishing emails to 347,000 customers using Trezor’s domain. The message, titled “Critical Security Alert: STM32 Entropy Vulnerability,” urged recipients to download an app and enter their wallet backup. Trezor said it took the domain down at the DNS level within 20 minutes, which limited exposure to 2,500 people who clicked the link before it was disabled. The company added that no other Trezor system was affected and that it has suspended its Brevo account to halt further distribution. The disclosure follows other recent incidents tied to Trezor’s third-party partners. Last month, the company said data from 11,742 customers was exposed after fulfillment partner ShipMonk was targeted. Last week, it said another 67,000 U.S. customers had names, email addresses, phone numbers, shipping addresses and order numbers leaked. Trezor also pointed to similar cases this year involving Ledger’s payment processor Global-e and a SafePal breach affecting about 39,798 customers’ order information.880
Trezor2026-09-10 07:15:14Trezor says third-party email provider was breached in phishing campaign using fake STM32 flaw alertHardware wallet maker Trezor said on Sept. 9 that one of its third-party email service providers had been breached, allowing attackers to send phishing emails that appeared to come through legitimate Trezor-linked mail infrastructure. The messages used the subject line "Critical Security Alert: STM32 Entropy Vulnerability" and claimed that devices using STM32 microcontrollers faced a serious entropy flaw that could weaken wallet backup security. Trezor said the warning was fake, told users not to click any links or enter wallet information, and added that it had shut down the affected domain while investigating how access to systems tied to its legitimate domain was obtained. Users who posted email headers on Trezor’s official forum said the messages were sent via mailing.trezor.io, while some also reported that the emails passed SPF, DKIM, and DMARC checks. Independent security research said some malicious links initially redirected through a Trezor mail-tracking subdomain. Separate research pointed to Brevo as the platform involved, but Trezor has not officially named the breached vendor. The incident follows Trezor’s earlier disclosure that logistics partner ShipMonk had been breached, a case that later expanded to about 81,000 affected customers after the company found old order data had been retained in ShipMonk’s systems.720
Bitcoin2026-09-09 16:16:04Mexican prosecutors say musician’s family was killed over Bitcoin cold wallet believed to hold millionsMexican prosecutors allege that two men targeted the home of Jonathan Meléndez, keyboardist for Camilo Séptimo, in search of a cold wallet they believed held millions of dollars in Bitcoin. The attack left Meléndez, his pregnant wife Ana Paula Barragán, their 3-year-old daughter Sofía, and 21-year-old domestic worker Aleyda Romero dead at the family home in Atizapán de Zaragoza, State of Mexico, on September 1, according to IBTimes UK. The couple’s 6-year-old son survived. Authorities identified the suspects as Diego Sebastián and Gerardo, withholding their surnames under Mexican criminal privacy rules. Prosecutors said Diego Sebastián, described as a business associate of Meléndez, used that relationship to gain access to the home and allegedly offered Gerardo 2 million pesos, about $118,000, to help obtain the crypto. Both men were arrested on September 2. The case adds to a rise in violent attacks against crypto holders. Chainalysis said it documented 46 violent crypto incidents through late June, with more than $30 million stolen in the first half of 2026. Home invasions made up 37% of those cases.780