GetChain News
中简 中繁 EN
GetChain News
Toggle sidebar

Online/Update

News linked to both this project and an event.

Trezor to Introduce Anonymous Hardware Wallet Delivery Option, Supporting Nickname Orders and Unbranded Packaging

Odaily News: Bitcoin News posted on X platform that, after a logistics provider data breach exposed the personal information of 13,689 customers, Trezor stated it is prioritizing the launch of an "anonymous delivery" option. Users can place orders using a nickname or tag ID, have devices delivered to automated parcel lockers, and receive them in unbranded packaging, with purchase information not linked to home addresses or real identities. Trezor plans to roll out this option in the EU in September and in the US by the end of the year.

Approximately 233,000 Bitcoin moved as a precaution, with around $15 billion involved following the Coldcard exploit

Odaily News: After a firmware vulnerability in Coldcard hardware wallets was exploited, approximately 2,100 Bitcoin were stolen, with losses nearing $130 million. On-chain data shows that in the days surrounding the incident, wallets held by long-term holders transferred out approximately 233,000 Bitcoin, valued at around $15 billion. Casa CEO Nick Neuman stated that some of the transferred funds came from Coldcard users migrating to multi-signature wallets, with Ledger and Trezor users also taking similar measures after the event. During the same period, approximately 22,000 Bitcoin were transferred into exchanges. Coinkite has advised users who generated seed phrases using firmware versions 4.0.1 through 4.1.9 to treat their wallets as compromised and immediately migrate to new seed phrases. These versions cover the period from March 2021 to July 2026. (Decrypt)

Crypto Companies Send Joint Letter to AI Labs, Urging Access to Frontier Models for Bitcoin Developers

据 Cointelegraph 报道,比特币政策研究所(BPI)联合 Anchorage Digital、BitGo、Bitwise、Blockstream、Kraken、Ledger、MARA、Trezor 等多家加密机构,发布公开信敦促各大前沿 AI 实验室为比特币及开源软件开发者建立或扩展可信访问计划。 信中指出,Bitcoin Core 等开源维护者目前缺乏对 AI 实验室网络安全程序的访问渠道,被迫依赖能力较弱的开源模型,而比特币网络当前保护着逾 1 万亿美元资产,任何开源基础设施漏洞均可能危及用户毕生积蓄。BPI 同时披露,已收到多份报告显示包括潜在境外势力在内的复杂攻击者正借助先进 AI 能力持续发动攻击。

Trezor user claims life savings stolen after clicking Google-sponsored phishing result

Bitcoin News posted on X platform that a Trezor user claimed their life savings were stolen after clicking a Google-sponsored search result impersonating Trezor. The phishing page was hosted on Google Sites and allegedly tricked the victim into entering their wallet recovery seed. Trezor stated that it is upgrading its handling of the report, proceeding with the removal of the website, and reminding users to never enter wallet backups or mnemonic phrases on any website or online form. Google-sponsored phishing ads remain an ongoing attack vector for crypto users.

Coldcard vulnerability-related losses may reach $130 million, hardware wallet manufacturers warn of increased phishing attacks

Odaily News: Hardware wallet manufacturers Trezor and Foundation have warned that following the disclosure of a Coldcard firmware vulnerability, phishing attempts targeting hardware wallet holders have increased, with attackers soliciting recovery phrases and luring victims into downloading malware. Security firm Proofpoint has detected phishing emails impersonating Coldcard, inviting users to complete a "hardware audit" with links to a cloned website. After clicking, users download a batch file hosted on GitHub that installs the remote access tool ScreenConnect. Proofpoint stated that the fraudulent website also features a customer service chat window, where real people guide victims through the installation process. This remote access tool can provide attackers with a pathway to steal data and funds, or further deploy malicious programs such as ransomware. Galaxy Research has confirmed three rounds of theft since July 30, with high-confidence losses of 1,596 BTC, exceeding $100 million; if a fourth round not yet confirmed with victims is included, total losses could reach $130 million.

$282 Million in Bitcoin and Litecoin Stolen in Trezor Impersonation Support Scam

Odaily News, January 10 - A Bitcoin and Litecoin holder provided a 12-word recovery phrase to attackers impersonating Trezor support personnel, resulting in the theft of approximately $282 million in assets, including about $139 million in Bitcoin and $153 million in Litecoin. Blockchain forensics firm ZeroShadow stated that the incident stemmed from a social engineering attack, not a compromise of wallet software or private key infrastructure. The stolen funds were split via the THORChain cross-chain bridge within minutes and converted into Monero through instant exchange services. ZeroShadow's monitoring team flagged and froze approximately $700,000 in funds within 20 minutes. Under the BIP39 standard, a 12-word recovery phrase contains approximately 128 bits of entropy, while a 24-word phrase contains 256 bits of entropy. Chainalysis estimates that up to 23% of all mined Bitcoin is permanently inaccessible due to lost keys, involving millions of BTC, with causes including forgotten recovery phrases, damaged backups, and a lack of inheritance planning.

Trezor Exec: Putting All Bitcoin into ETFs Might Be the Worst Outcome for the Industry, Undermining the Core Principle of Self-Custody

: Danny Sanders, Chief Business Officer of hardware wallet manufacturer Trezor, stated that "putting everything into ETFs" might be the worst development path for the Bitcoin ecosystem. Since the launch of US spot Bitcoin ETFs in early 2024, cumulative inflows have exceeded $53 billion, making them a significant driver of BTC prices, but also potentially altering the structure of how users hold their assets.Sanders believes that over-reliance on ETFs will weaken Bitcoin's core principle of "self-custody," gradually shifting asset control to third-party institutions instead of users holding their private keys. Although self-custody carries risks such as lost seed phrases or unrecoverable private key leaks, he considers these more of a psychological barrier than a technical challenge, adding that "it's not difficult once you actually start doing it."Data shows that out of approximately 600 million crypto users globally, only about 10% practice self-custody, and only around 12 to 13 million users employ hardware wallets.As an early hardware wallet provider in the industry, Trezor helped popularize the BIP-39 seed phrase standard and continues to advocate for lowering the barriers to self-custody through improved user experience and educational tools, rather than relying on intermediary custody.Sanders concluded that the industry's long-term goal should be to gradually approach a Web2-level user experience, rather than simply replacing self-custody with ETFs. "That would probably be the worst possible outcome for the entire industry." (The Block)

Trezor Safe 7’s Chip Has a Hardware Vulnerability, Team Says User Funds Are Safe

Ledger's Donjon security research team successfully bypassed the firmware verification system of the TROPIC01 chip inside the Trezor Safe 7 using laser attacks in a laboratory setting. Chip manufacturer Tropic Square subsequently discovered another attack path affecting the chip's MAC-and-Destroy security mechanism. This vulnerability currently impacts all TROPIC01 chips in production within the field. Trezor stated that the TROPIC01 chip is one of three independent security layers within the Trezor Safe 7, and user funds, wallet backups, and private keys are not stored on it.The chip's hardware encryption storage mechanism completely withstood Ledger's extraction attempts during initial testing. Tropic Square has delayed the release of technical details regarding the vulnerability until the launch of a reinforced silicon version of the TROPIC01 chip later in 2026, with full details expected to be disclosed in the spring of 2027.A firmware mitigation is currently available by disabling the chip's MAINTENANCE mode. Trezor CEO Matej Zak stated that PINs, wallet backups, and user fund keys have never been stored on a single chip. (The Block)

Ethereum Foundation Launches Clear Signing Open Standard, Enabling Human-Readable Transaction Signatures by Default

The Ethereum Foundation announced that Clear Signing has officially launched, aiming to eliminate “blind signing” by defaulting Ethereum transaction signatures to human-readable formats—thereby enhancing both user experience and security. Spearheaded by the Ethereum Working Group, the initiative includes: ERC-7730 for generating human-readable transaction descriptions; a neutral, mirrorable descriptor registry; ERC-8176, a proof framework enabling auditors to verify descriptor integrity; and open development tools for wallets, protocols, and auditors. Participants include Ledger, Trezor, MetaMask, and WalletConnect.