VYPR
breachPublished Sep 10, 2026· 2 sources

Trezor Warns of Phishing Attacks After Email Provider Breach; Liquid Pauses Operations Amid $320M Bitcoin Withdrawal

Hardware wallet manufacturer Trezor has alerted customers to phishing attempts following a breach of its email service provider, while cryptocurrency exchange Liquid has halted network operations after a massive $320 million Bitcoin withdrawal.

Hardware wallet manufacturer Trezor has issued a critical warning to its customers, advising them to be vigilant against sophisticated phishing attacks. The alert comes in the wake of a security incident where attackers compromised Trezor's third-party email service provider, gaining access to customer data. These attackers are now leveraging this access to distribute fraudulent emails that falsely claim a flaw exists in Trezor devices, potentially exposing users' wallet recovery phrases.

The deceptive emails are designed to appear as legitimate communications from Trezor's official support channels. They urge recipients to address an alleged security vulnerability related to a specific chip used in the wallets. Trezor has explicitly stated that these messages are fake and strongly advises customers against clicking any links or providing any information. The company has since taken down the domain used in the phishing campaign and is actively investigating the root cause of the breach into its legitimate email system. This incident follows a previous breach involving shipping provider ShipMonk, which also exposed customer information, affecting approximately 81,000 U.S. customers and some international users.

In a separate, significant event within the cryptocurrency space, the Liquid Network has paused all network activity following an unprecedented withdrawal of approximately 4,000 Bitcoin, valued at around $320 million. This substantial withdrawal represents nearly 95% of Liquid's reported Bitcoin reserves prior to the incident. Liquid has stated that the funds were removed using a key designated for approving Bitcoin transfers out of the network, but emphasized that the key itself was not compromised. The exact nature of the weakness that facilitated this massive withdrawal remains unexplained by the network.

A message accompanying one of the Bitcoin transactions indicated that the parties responsible for the withdrawal identified themselves as "white-hat hackers." Blockstream, the technology provider for Liquid, is reportedly attempting to establish contact with these individuals through signed blockchain messages. In response to the incident, Liquid has temporarily disabled transaction-submitting bridge nodes. Furthermore, cryptocurrency exchanges have suspended all deposits and withdrawals for LBTC, Liquid's Bitcoin-backed token, though other assets on the network have not been affected.

Adding to the week's cryptocurrency-related news, a 22-year-old Singaporean national has pleaded guilty in U.S. federal court for his role in an international fraud scheme that pilfered over $245 million in cryptocurrency. Malone Lam, residing in Miami, admitted to participating in a federal racketeering conspiracy. Prosecutors allege that Lam led a network that employed social engineering tactics to target victims, identifying them and coordinating other group members. Lam faces a maximum prison sentence of 20 years, with a status hearing scheduled for December 8.

Finally, India's Financial Intelligence Unit has issued notices to 15 cryptocurrency platforms for operating within the country without adhering to anti-money laundering (AML) regulations. The agency is also seeking to block public access to the applications and websites of these platforms, which include Weex, Blofin, Bitunix, DigiFinex, Toobit, XT.com, WOO X, and WhiteBIT, among others. India mandated AML compliance for virtual digital asset service providers, including crypto platforms, in March 2023, requiring registration and reporting even for entities without a physical presence. Several major exchanges have previously adjusted their operations to meet these requirements, with Binance and Bybit returning to the Indian market after compliance measures were met.

This new report indicates that the phishing campaign, stemming from a breach at a shared email provider, has also impacted customers of CoinTracking and BitBox, in addition to Trezor. The compromised provider sent corrupted messages to subscribers across these platforms, increasing the potential attack surface for malicious actors.

Synthesized by Vypr AI