High Alert

Attackers exploit fake STM32 vulnerability alert to target Trezor and BitBox holders

Written and edited by the WorldPing NewsdeskPublished Updated Original reporting: CryptoSlate
Attackers exploit fake STM32 vulnerability alert to target Trezor and BitBox holdersWorldPing
Image via CryptoSlate.

What happened

Trezor confirms an email-provider breach and says its wallets remain safe, while BitBox investigates a likely newsletter-provider compromise.

Key facts

  • Reported by CryptoSlate and published Fri, 11 Sep 2026 08:10:54 UTC.

Why it matters

Digital-asset markets react to catalysts within minutes, and liquidity, ETF flows and regulatory signals are usually what decide whether a move sticks.

What to watch next

  • Whether spot volume and open interest confirm the move
  • Liquidation clusters around the current price
  • ETF flow data and any regulatory follow-up

Coverage timeline

When each newsroom published on this story, oldest first — all times UTC.

  1. Brevo login flaw enabled phishing email targeting 347K Trezor subscribers

  2. Revised CLARITY Act targets ‘non-decentralized’ DeFi operators

  3. Quantus Targets $2.7 Trillion Crypto Risk With Quantum-Safe Mainnet

  4. Attackers exploit fake STM32 vulnerability alert to target Trezor and BitBox holders

  5. ‘Return the bitcoin’: Blockstream refuses ransom demand for remaining 600 BTC from Liquid exploit

Sources

The original report was published by CryptoSlate. WorldPing does not claim that reporting — this page summarises and contextualises it.

Read the full report at CryptoSlate

Related WorldPing coverage

Russia targets Kyiv petrol stations for first time with jet-powered dronesWorldPing
The Guardian

Russia targets Kyiv petrol stations for first time with jet-powered drones

Three facilities in two days struck as bombardment of Ukraine’s capital enters new phase of intensity Europe live – latest updates Petrol stations in Kyiv have been hit by jet-powered drones in a wave of targeted Russian attacks as the bombardment of…

Brief by WorldPing · Original reporting by The Guardian