Dudent

Market Prices

BTC Bitcoin
$75,816.7 -2.84%
ETH Ethereum
$2,402.91 -4.46%
SOL Solana
$97.1 -5.49%
BNB BNB Chain
$715.1 -0.54%
XRP XRP Ledger
$1.29 -9.36%
DOGE Dogecoin
$0.0801 -4.38%
ADA Cardano
$0.1950 -6.47%
AVAX Avalanche
$7.26 -4.26%
DOT Polkadot
$0.9418 -6.15%
LINK Chainlink
$10.92 -5.58%

Event Calendar

{{年份}}
22
03
unlock Optimism Unlock

Circulating supply increases by about 2%

08
04
upgrade Solana Firedancer

Independent validator client goes live on mainnet

10
05
upgrade Ethereum Pectra Upgrade

Raises validator limit and account abstraction

18
03
unlock Sui Token Unlock

Team and early investor shares released

28
03
unlock Arbitrum Token Unlock

92 million ARB released

30
04
upgrade Celestia Mainnet Upgrade

Improves data availability sampling efficiency

12
05
halving BCH Halving

Block reward halving event

15
04
halving Bitcoin Halving

Block reward reduced to 3.125 BTC

Tools

All →

Altseason Index

42

Bitcoin Season

BTC Dominance Altseason

Market Cap

All →
# Coin Price
1
Bitcoin BTC
$75,816.7
1
Ethereum ETH
$2,402.91
1
Solana SOL
$97.1
1
BNB Chain BNB
$715.1
1
XRP Ledger XRP
$1.29
1
Dogecoin DOGE
$0.0801
1
Cardano ADA
$0.1950
1
Avalanche AVAX
$7.26
1
Polkadot DOT
$0.9418
1
Chainlink LINK
$10.92

🐋 Whale Tracker

🔵
0xd192...d55c
6h ago
Stake
2,551,080 USDC
🟢
0xb164...c449
1d ago
In
1,866 SOL
🔴
0x56aa...0cc3
12h ago
Out
9,533,994 DOGE

The Fake Security Alert: Trezor, BitBox, and the Newsletter Vendor Nobody Put on the Threat Model

Wallets | ProPrime |
Two hardware wallet vendors. One shared service provider behind them. Zero confirmed victims — publicly, at least. Trezor and BitBox have both warned users about fraudulent hardware wallet security alerts arriving in their inboxes. BitBox's disclosure carries the only structural detail worth analyzing: multiple Bitcoin companies appear to have been targeted through a shared newsletter service provider. Trezor's contribution is a single sentence — its email service was compromised. That is the entire public record. No timestamps. No victim count. No attacker attribution. No third-party forensics. Three information points, and one of them is the whole story. Data over drama. Here is what the disclosure actually tells us, and what it deliberately does not. Trezor, built by Prague-based SatoshiLabs, has shipped since 2013. BitBox, built by Switzerland's Shift Crypto, since 2018. Neither issues a token. Both sell a physical device, once, at a one-time price, and both stake their entire commercial existence on a single intangible claim: your keys never leave the device. That is the business model, in full. No emissions. No staking yield. No unlock schedule. No governance attack surface. Revenue is hardware margin. Reputation is the balance sheet. Both companies keep their firmware open precisely because reputation is the only thing they can collateralize. The category is small and reputation-priced. Ledger holds the largest shipped base. Trezor sits in the top tier with a long history and an open firmware lineage. BitBox occupies a narrower, more privacy-oriented niche with a strong reputation among Bitcoin maximalists. Coldcard and Keystone serve the air-gapped, multi-signature crowd. None of these companies compete on features in any meaningful way. They compete on the answer to one question: do I trust you with my keys. Every incident like this is a withdrawal from that account, and the account is not insured. The sector is also concentrating its trust into fewer hands, which is precisely the direction that makes shared-vendor risk worse. I live in Prague. I have watched SatoshiLabs operate out of this city for years. When I liquidated every leveraged position in March 2022 and moved what remained into self-custody, the seed phrase stopped being a backup and became the counterparty. A hardware wallet is where that counterparty physically lives — a small piece of plastic holding the difference between a position and a loss. Bear markets change who carries that plastic. Self-custody inflows rise when trust in intermediaries falls, and the audience reading this is larger and more exposed than the audience reading it in 2021. That is why a phishing advisory matters more this cycle than it did last cycle. So understand what an attack on a hardware wallet vendor actually attacks. Not secp256k1. Not the secure element. The notification channel between vendor and user — a marketing SaaS product, staffed by people you will never meet, holding a list of email addresses belonging to people who own real bitcoin. Start with the threat model, because the disclosure's framing invites the wrong one. The device was not broken. Nobody extracted a seed from a Trezor or a BitBox. The assumptions that failed sit one layer up: first, that a message claiming to come from your wallet vendor actually came from your wallet vendor; second, that a shared third-party service provider counts as a business tool rather than a security boundary. BitBox's language should be read slowly. Multiple Bitcoin companies were targeted through a shared newsletter service provider. Read that against the standard diversification argument. Holders are told to spread custody across vendors so that one compromise cannot reach everything. That logic holds at the device layer. It collapses at the SaaS layer. If four competing vendors rent the same newsletter infrastructure, the competition is real and the isolation is not. This is the SolarWinds pattern. The MOVEit pattern. The 3CX pattern. In Web3, the nearest precedent is December 2023's Ledger Connect Kit injection, where a compromised connector library drained roughly $600,000 before the malicious build was pulled. Same anatomy both times: trust injected at a layer nobody audits, propagated outward under a brand everyone already trusts. Two reported facts sit adjacent in the coverage and may be one fact. Trezor reports its email service was compromised. BitBox reports a shared provider was used to target multiple Bitcoin companies. The method is identical in both cases — a forged security alert — and the reporting places them together. The parsimonious reading is a single campaign against a single vendor serving, at minimum, two competing hardware wallet companies. That is unconfirmed. It is also the reading that best explains why two firms that compete on trust published warnings in the same news cycle. Now the funnel math. Assume the provider held a subscriber list. Suppose it is 100,000 addresses, and a security-themed lure pulls a 1% to 3% click rate — unremarkable for this category. That is 1,000 to 3,000 humans landing on a page telling them their funds are at risk and their firmware is outdated. Conversion from landing to seed entry, on a page styled as an official recovery flow, does not need to be high. At half a percent, 500 seed phrases. The attacker does not need the list. They need the tail of it. Those figures are illustrative. The structure is not. Marginal cost per additional victim at the delivery stage is effectively zero, and the value of a single compromised seed phrase is unbounded. That asymmetry is why this vector keeps working and will keep working. There is a second-order failure that matters more than the first. Once a vendor's security notifications travel through a channel demonstrated to be forgeable, the notification loses evidentiary value. The next genuine firmware advisory — the one that actually matters — lands in an inbox where the user has been trained, correctly, to distrust it. Trust in a channel is a one-way ratchet. One more branch, flagged as inference rather than fact. If the compromised asset was a subscriber list rather than a delivery pipe, the attacker now holds a curated index of self-identified hardware wallet owners. That list has resale value long after this campaign ends, and it enables a category of risk that never appears on a price chart: targeted physical threats against known holders. Numbers don't lie. Neither does their absence. No timestamp means the incident cannot be correlated to a firmware release, a listing window, or a market event. No victim count means the second-order loss is unmeasured. No attribution means we cannot distinguish one campaign against one provider from repeated probing of an entire sector. In incident disclosure, silence on those three axes is not neutral. It is the default posture of private companies with no disclosure obligation, and it means the market will underprice the event for lack of numbers to price against. The fix is boring and available today. Sign security communications with a vendor key and publish the fingerprint in firmware and on the device screen. Push critical alerts through the companion app and the hardware itself. Treat email as a marketing channel and nothing more. Almost nobody does this, because signing costs engineering time and email converts better. The consensus reading is that users were careless or vendors were sloppy. Both framings are too comfortable. The uncomfortable reading: the vendor was not sloppy. The vendor did the rational thing. It bought a newsletter service because building one is not its business, and it hardened the product because that is what customers pay for. The failure was structural, not individual. Shared infrastructure is efficient right up to the moment it is shared with your competitor's attacker. The brand was the payload, and that is the part the industry has not internalized. A second blind spot sits on the user side. The self-custody community treats open-source firmware as the terminal security claim. Both vendors ship it. It is genuinely valuable. It is also entirely irrelevant to whether the email in your inbox is real, because the attack never touches firmware. Open source verifies code. It does not verify a notification, and it does not verify a sender. There is a market blind spot worth naming too. Holders should not trade this headline, and I say that as someone who trades headlines for a living. There is no token here. SatoshiLabs and Shift Crypto are private. Comparable events — Ledger's 2020 customer data leak, the 2023 Connect Kit injection — produced no measurable, persistent price impact on major assets. Liquidity vanishes. Lessons remain. This is a lesson, not a trade. Where it leaves a mark is share. After Ledger's 2020 leak, privacy-sensitive holders drifted toward vendors supporting anonymous purchasing. This time, two vendors associated with exactly that refuge were hit at once. The plausible beneficiaries are the vendors outside the blast radius. Expect drift, not a step change. Hardware wallet users carry high switching costs and low switching frequency. Anyone modeling a sharp share shift is modeling sentiment, not behavior. Strip it to behavior. Treat every unsolicited security alert as hostile until verified on the device screen. Never enter a seed phrase anywhere except the hardware device itself — including on a page that looks exactly like your vendor's. Check advisories by typing the domain, never by clicking. If your vendor still routes security notices through unsigned email, discount them accordingly. Your keys are safe. Your inbox is not. For the vendors, the question is not whether to apologize. It is whether email remains an acceptable channel for security-critical communication. Industry-wide, right now, it is the default. That is the vulnerability. Calculate. Execute. Repeat. The threat was never the cryptography. It is the plumbing nobody wrote into the threat model — and until notifications are signed or the channel is abandoned, every urgent security update in your inbox is an unverified claim from an unidentified sender. Verify, then act. Never the reverse.

The Fake Security Alert: Trezor, BitBox, and the Newsletter Vendor Nobody Put on the Threat Model

Fear & Greed

51

Neutral

Market Sentiment

Gas Tracker

Ethereum 28 Gwei
BNB Chain 3 Gwei
Polygon 42 Gwei
Arbitrum 0.5 Gwei
Optimism 0.3 Gwei

💡 Smart Money

0xd2c9...d68e
Market Maker
+$3.5M
78%
0xadee...9c13
Market Maker
+$4.5M
68%
0x8e92...932d
Institutional Custody
-$0.3M
83%