Trezor2026-09-28 14:32:00Bitcoin Magazine Review Says Trezor Safe 7 Sits Between Open-Source Self-Custody and Mainstream Hardware DesignBitcoin Magazine has published an extensive review of the Trezor Safe 7, describing the device as a middle-ground option between fully open-source, self-custody-first hardware wallets and more consumer-oriented products built around polished design and user guardrails. The review highlights the wallet’s metal body, large edge-to-edge screen, tactile approval flow, and dual firmware approach, with separate multi-coin and Bitcoin-only stacks that users can switch between regardless of the device color they bought. A major focus of the piece is Trezor’s use of 20-word SLIP-39 backups and the company’s Shamir backup system. According to the review, the extra words do not increase entropy beyond the 128 bits users would expect from a 12-word seed, but they enable migration from a single-seed setup to Shamir shares without moving funds on-chain. The article also covers Safe 7’s Bluetooth support, Qi2 wireless charging, LiFePO₄ battery choice, and the security trade-offs that come with moving away from a stricter air-gapped model. The review further examines Safe 7’s four entropy sources, the absence of direct user-supplied entropy at wallet creation, and Trezor’s comments on why that design remains under discussion. It also points to the recent ShipMonk data breach affecting 67,000 U.S. customer records and notes Trezor’s plan to roll out an anonymous delivery option in the EU within weeks, followed by the U.S. soon after.260
crypto scams2026-09-28 11:02:00Fake Mainnets, Poisoned Addresses and Drainers: A 2026 Guide to Common Crypto ScamsPANews published a long-form scam guide by Biteye that uses the fake GIWA mainnet incident as its opening case and then walks through several of the most common fraud patterns seen in crypto in 2026. The piece argues that the most dangerous part of today’s scam market is not just technical sophistication, but the constant ability of attackers to reshape old tricks into forms users have not seen before. The article breaks the risks into several buckets: phishing links amplified on X, fake hiring and investment outreach that leads targets to run malware, hijacked KOL accounts used to launch tokens or promote trades, Telegram impersonation and account takeovers, fake Google search results, Discord verification drainer flows, email airdrop lures, address poisoning, fake mainnets and fake bridges, malicious apps, and exchange account resets obtained with forged identity materials. Among the concrete cases cited, the GIWA scam stands out. According to the article, GIWA had disclosed Chain ID 9134, but its mainnet had not officially launched and there was no official RPC or bridge. Attackers built a fake “GIWA Mainnet” using the real Chain ID, and 1,335 addresses eventually sent about 767.65 ETH to it. Roughly 766.25 ETH was drained, for losses approaching $2 million.740
Bitget2026-09-28 07:47:36Bitget CEO says protection fund will be restored to more than $300 million within a weekBitget CEO Gracy Chen said during a livestream reviewing the incident that unauthorized transfers took place at 2:31 a.m. Beijing time on Sept. 25 across multiple chains, affecting assets held in parts of the exchange’s hot-wallet and warm-wallet infrastructure. According to the company’s investigation, the attacker exploited a vulnerability in a third-party security product, stole internal credential access, and forged withdrawal instructions to the wallet system, bypassing risk-control checks. Chen said private keys were not compromised and cold wallets were not affected. She added that the attack path has been identified, the vulnerability has been fixed, and the situation is now fully under control. Bitget said about $388 million in assets was transferred out. The attacker’s addresses and on-chain tracking data have already been disclosed. Chen also said the full loss will be covered by Bitget’s user protection fund, and the company will replenish that fund to at least $300 million within one week after it is used. Bitget has also started an asset recovery plan and said it will share confirmed vulnerability and attack details with relevant industry parties while continuing to disclose tracking updates.220
Magic Eden2026-09-25 16:12:07White Hats Secure 23,155 NFTs After Legacy Magic Eden Approvals Are ExploitedLegacy approvals tied to Magic Eden were exploited, prompting white-hat responders to move affected assets into safer custody. According to TheDefiant, Yuga Labs’ 0xQuit said 23,155 NFTs with a value of more than $5.7 million had been secured. The figure points to a large-scale rescue effort rather than a completed fix for all exposed wallets. The report also said holders still need to take action on their own side. Users are advised to revoke NFT and token approvals connected to the vulnerable contracts, as those permissions remain a risk even after part of the inventory has been protected by white hats. The incident centers on older approvals, not a broad new description of the marketplace itself in the source material. At this stage, the key facts in the report are the number of NFTs secured, the estimated value involved, and the warning that wallet owners must revoke the affected approvals.270
CoinEx2026-09-25 09:47:09ViaBTC CEO Yang Haibo says CoinEx hot wallet design used MPC-based dual signaturesViaBTC founder and CEO Yang Haibo said in a post that CoinEx is shutting down, but argued that the exchange’s hot wallet system remains advanced enough to serve as a reference for the industry. According to Yang, CoinEx introduced an MPC-based dual-signature setup for its hot wallet architecture to remove single points of failure. He said the underlying infrastructure was split into a business system and a wallet system, each operated by a fully independent team holding one private key. Every withdrawal or transfer had to pass real-time, substantive risk-control reviews on both sides. Under that design, Yang said, compromising either system alone would not allow an attacker to steal assets. Yang also said the wallet signing process had to be implemented independently rather than relying on the native mechanisms of each node, which required extensive rebuilding work. He added that the team spent more than a year modifying most of the nearly 300 blockchains supported by CoinEx.260
SlowMist2026-09-22 07:31:33SlowMist flags job-interview phishing campaign disguised as a Web3 hiring processSlowMist said attackers are posing as Web3 companies and using remote job interviews as bait to get candidates to deploy and run a local project. The project is presented as RoyalCity, a real estate and crypto investment app, but its tailwind.config.js file contains obfuscated malicious code. Once the project is run or built, the payload can steal browser credentials, wallet extension data, exfiltrate local files, monitor clipboard content, and enable remote control of the victim’s machine. SlowMist also said errorHandler.js contains a separate server-side backdoor that can retrieve and execute remote code. According to the security team, the case closely resembles a previously analyzed recruitment-themed GitHub poisoning attack: both used interview lures, executed through Tailwind, and carried highly similar data theft and remote access payloads. The disclosure was published by @SlowMist_Team and carried by Techub News.430
SlowMist2026-09-22 03:10:39SlowMist and OKX say App Store-listed FomoPeek versions 1.1 and 1.2 carried an iOS exploit frameworkSlowMist and the OKX security team said their joint analysis found that FomoPeek, an on-chain whale-tracking app distributed through Apple’s App Store, included a full iOS kernel attack framework in versions 1.1 and 1.2. According to the report, users did not provide mnemonic phrases and did not sign any transactions, yet their assets could still be stolen. SlowMist’s MistTrack data showed a main hacker address active since Sept. 15 that had received 579,984.34 USDT as of publication, with funds still flowing in. The researchers said the malicious components were shipped inside the official App Store builds rather than spread through re-signing or sideloading, and that the framework could communicate with attacker-controlled servers, exploit kernel flaws, escape the sandbox, decrypt Keychain data and collect information across apps. The report also said the command-and-control server targeted 19 wallet and note-taking apps, including Gate Web3, SafePal, OKX Wallet, MetaMask, Trust Wallet, imToken, TokenPocket, TronLink and Apple Notes. SlowMist advised users who installed versions 1.1 or 1.2 to treat old mnemonic phrases and private keys as compromised and move assets to a newly created wallet on a clean device.710
SlowMist2026-09-21 19:20:46SlowMist warns Darksword exploit may now target iOS 26.5 and steal wallet private keysSlowMist Chief Information Security Officer 23pds said attackers are exploiting the Darksword vulnerability through Safari to bypass iOS security protections, take control of devices, and extract private keys and other data from self-custodied crypto wallets. The flaw had previously been used in attacks targeting users in Saudi Arabia, Turkey, Malaysia, and Ukraine. Google Threat Intelligence Group had earlier disclosed that Darksword originally affected iOS 18.4 through 18.7. According to 23pds, attackers have now adapted the exploit to iOS 26.5, though that claim has not been officially verified. The attack chain typically starts with social engineering: once a user clicks a malicious link sent through social media or messaging apps, the device may be rooted and wallet data extracted. SlowMist urged users to update their phones promptly and avoid visiting links sent by strangers. Separately, Bitcoin.com News reported that three investors who downloaded fake wallet apps from Apple’s official App Store lost nearly $1.8 million in Bitcoin and have sued Apple.410