EN ▼
Favorites
My Favorites
View All
Market Cap Price 24h%

Disclaimer: Content does not constitute investment advice. Trading involves risks—please invest with caution!

Refusing to pay ransom and exposing a vendor breach that was not caused by Trezor itself

2026-09-12 04:12:52
Bookmark

Blockstream refuses extortion, Trezo vendor leak highlights new cryptographic security challenges

Regarding the approximately 598 to 600 bitcoins still missing from the Liquid Network vulnerability incident, Blockstream explicitly rejected the extortion request and said it would fill the funding gap itself.

Trezor disclosed that a login credentials breach occurred at Brevo, its third-party mail service provider, allowing attackers to send phishing emails to approximately 347,000 newsletter subscribers. Trezor emphasized that the Brevo break did not touch Trezor's own infrastructure, hardware devices or user wallets.

These two incidents this week highlight two different dimensions of the crypto industry in the security arena: on the one hand, they involve how companies respond after being attacked by vulnerabilities, and on the other hand, they reveal how vulnerabilities from third-party vendors put users at risk without touching the cryptocurrency company's own systems.

Blockstream refused to pay ransom, characterizing it as theft rather than negotiation.

Blockstream said it would not pay ransom demands related to the approximately 598 to 600 remaining bitcoins in the Liquid Network sidechain breach. It is estimated that the initial amount stolen was close to $320 million. According to reports, the attackers had demanded payment of about 10% of the remaining funds in exchange for the return of the rest. This structure is sometimes used as an informal negotiation tool in encryption breaches, where attackers package the theft as an "uninvited security assessment" that claims to be compensated rather than treated as a crime.

Blockstream directly refuted the claim, characterizing the funds as stolen property rather than negotiable objects, and stating that it would cover losses from the company's own resources rather than rewarding actors who exploit the exploit.

This position sends a clear signal of transcending a single event. In the world of crypto security, payment of ransoms or bounties to exploit vulnerabilities, even disguised as white-hat negotiations, has been controversial: some agreements have been used to recover most stolen funds, but critics believe they would normalize exploitation and become a low-risk, high-return avenue. Blockstream's refusal demonstrates its firm view of such exploits as pure theft. Given that other agreements have established contrary precedents in past events, this position has important reputational weight.

Trezor Incident: Third-Party Supply Chain Risk

Trezor's situation falls into a completely different risk category. Trezor disclosed that a login credential breach occurred in Brevo, a third-party mail service provider it uses to send newsletters, causing attackers to obtain subscriber data and send phishing emails to approximately 347,000 Trezor newsletter subscribers.

Trezor pointed out in his incident disclosure that other companies that use Brevo services, such as BitBox and CoinTracking, were also affected by the same underlying vulnerability. This suggests that the problem lies with the vendor, not with any individual cryptocurrency company's own systems. Trezor made it clear that the breach did not directly affect its physical infrastructure, hardware devices or user wallets; the risk to subscribers comes entirely from the phishing emails themselves, which may attempt to trick recipients into revealing mnemonics or approving malicious transactions.

Industry Revelation: Security boundaries move out

This incident reminds us that most of the security aspect of the encryption industry has extended beyond the company's own infrastructure and exists among relying third-party providers, such as service providers for email delivery, customer support, or data analysis. A hardware wallet manufacturer can make truly secure devices, but still expose its customer base to targeted phishing attacks due to vendor vulnerabilities that cannot be controlled and directly repaired.

For anyone receiving a newsletter email from a hardware wallet provider, the practical lesson is consistent with the advice after most phish-related vulnerability incidents: Be more vigilant about unexpected security alerts or login prompts received via email, and verify any urgent requests through the company's official app or website, and never click on links in the email directly.

Disclaimer:

All content published on this website, including hyperlinks, related applications, forums, blogs, and other media accounts, originates from third-party platforms and their users. CoinMarketInsight makes no representations or warranties of any kind regarding the website or its content. All blockchain-related data and materials are provided for informational and research purposes only and do not constitute financial, legal, or investment advice. Users and third parties are solely responsible for the content they publish. CoinMarketInsight shall not be liable for any losses arising from the use of this website. You should exercise caution and conduct your own independent research, review, analysis, and verification before making any decisions.

Read Full Article
More News
TOP

TOP