Bitget lost about $387.5 million to forged withdrawals from its wallet system, more than half of September's $742 million in crypto thefts. Most of Liquid Network's loss was handed back, so what stayed stolen sits mainly with one exchange's withdrawal infrastructure.
Reality
- Evidence58
- Adoption
- Insufficient
- Hype gap+8
- Incentives
- Insufficient
- Confidence55
Hester Peirce used her penultimate week as an SEC commissioner to urge replacing bulk KYC collection with zero-knowledge proofs of eligibility. She filed no proposal and spoke for herself, so the collection rules she criticized stay as written.
Perspective Coverage
3 publishers
- Builder
- Builder 35%
- Operator
- Operator 37%
- Investor
- Investor 28%
Reality
- Evidence62
- Adoption
- Insufficient
- Hype gap+25
- Incentives50
- Confidence65
A fulfillment partner exposed names, addresses and phone numbers belonging to hardware wallet buyers, according to The Register. The vendor's boundary was the company's boundary.
Perspective Coverage
3 publishers
- Builder
- Builder 28%
- Operator
- Operator 55%
- Investor
- Investor 17%
Reality
- Evidence70
- Adoption
- Insufficient
- Hype gap+5
- Incentives60
- Confidence68
The wallets held. The customer list did not: 39,798 names, phone numbers and shipping addresses, taken through commerce plumbing nobody threat-models.
Perspective Coverage
3 publishers
- Builder
- Builder 28%
- Operator
- Operator 55%
- Investor
- Investor 17%
Reality
- Evidence68
- Adoption
- Insufficient
- Hype gap+10
- Incentives55
- Confidence70
Roughly 40,000 SafePal customers had names, addresses and payment methods exposed, according to Crypto Briefing; the air-gapped device held, the shipping list did not.
Perspective Coverage
4 publishers
- Builder
- Builder 24%
- Operator
- Operator 55%
- Investor
- Investor 21%
Reality
- Evidence75
- Adoption
- Insufficient
- Hype gap+10
- Incentives40
- Confidence70
No seed phrases were touched. What was taken is names, phone numbers and shipping addresses for people known to own a hardware wallet, now advertised on a crime forum.
Perspective Coverage
8 publishers
- Builder
- Builder 21%
- Operator
- Operator 70%
- Investor
- Investor 9%
Reality
- Evidence62
- Adoption
- Insufficient
- Hype gap+10
- Incentives55
- Confidence68
The records that expanded Trezor's breach were US orders from 2019 to 2021, held years past the 90-day deletion window its fulfillment partner had promised, which puts the failure in the contract rather than the device.
Reality
- Evidence60
- Adoption
- Insufficient
- Hype gap+15
- Incentives60
- Confidence58
The records cover orders placed between November 2019 and August 2021, years past the 90-day deletion window Trezor advertises. Trezor says it held repeated written confirmation from ShipMonk that the data was gone.
Perspective Coverage
3 publishers
- Builder
- Builder 30%
- Operator
- Operator 55%
- Investor
- Investor 15%
Reality
- Evidence62
- Adoption
- Insufficient
- Hype gap+8
- Incentives64
- Confidence66
Brevo says an intruder reached 120 customer accounts and used them to mail phishing from those customers' own domains. Three crypto companies confirmed their newsletter lists were hit. Only one named the provider.
Perspective Coverage
4 publishers
- Builder
- Builder 15%
- Operator
- Operator 69%
- Investor
- Investor 16%
Reality
- Evidence68
- Adoption
- Insufficient
- Hype gap−20
- Incentives40
- Confidence70
The request came from an unauthorized account on a real government domain, and Revolut acted on it. The company calls the number of affected customers limited, and it declined to say how many or name the agency.
Perspective Coverage
5 publishers
- Builder
- Builder 23%
- Operator
- Operator 55%
- Investor
- Investor 22%
Reality
- Evidence68
- Adoption
- Insufficient
- Hype gap+10
- Incentives55
- Confidence66
Brevo says a long-lived Cloudflare key with full account permissions sat in its application source code, and the Worker built with it stripped Content-Security-Policy headers from scripts that Sansec estimates reach 100,000 sites.
Perspective Coverage
3 publishers
- Builder
- Builder 34%
- Operator
- Operator 48%
- Investor
- Investor 18%
Reality
- Evidence78
- Adoption60
- Hype gap+20
- Incentives58
- Confidence72
The payment firm says its servers went dark on September 14 after an intruder probably reached internal systems, and that customer emails, IBANs, transaction histories and hashed passwords may have been exposed.
Reality
- Evidence34
- Adoption38
- Hype gap+18
- Incentives68
- Confidence45
Brevo closed the SAML vector and reset active sessions by about 8:30 UTC on 10 September. Six of the 138 breached accounts sent phishing mail, and Trezor counted roughly 347,000 recipients in a single day.
Reality
- Evidence48
- Adoption62
- Hype gap+12
- Incentives55
- Confidence45
Greenberg Traurig says an intruder took client documents and posted them on the dark web. The doubling behind that story is nearly 60 law-firm matters inside BakerHostetler's 1,250-incident book for 2025.
Reality
- Evidence52
- Adoption63
- Hype gap+22
- Incentives62
- Confidence55
The email telling Trezor owners their recovery phrases might lack entropy came from a real trezor.io address and passed DKIM, SPF and DMARC, and it described a defect close to the one that took 1,778.84 BTC from Coldcard users.
Reality
- Evidence42
- Adoption55
- Hype gap+22
- Incentives58
- Confidence45
Both wallet makers say AI is shortening the distance between finding a bug and using one, which makes the pace of their own coordinated disclosure the number worth pricing, and the only loss they cite belongs to a rival vendor.
Reality
- Evidence34
- Adoption22
- Hype gap+33
- Incentives82
- Confidence33
Socket says the operators bought their way onto tens of thousands of machines and delivered the payload in a routine update. Cleanup means rotating passwords and moving crypto to fresh wallets, user by user.
Reality
- Evidence52
- Adoption34
- Hype gap+12
- Incentives62
- Confidence50
An extension allowlist pins an ID, and the ID survives a sale. The operators behind Superior bought or seeded trust that users had already granted, then spent it in an automatic update that stripped page CSP on the way through.
Reality
- Evidence55
- Adoption40
- Hype gap+12
- Incentives55
- Confidence50
Trezor's hardware held, but its logistics vendor gave away the one input an AI phishing operation otherwise has to guess at: a payment-verified list of buyers, 11,742 of them with full contact details.
Reality
- Evidence34
- Adoption41
- Hype gap+27
- Incentives66
- Confidence37
Rapid7's Operation ASTERIX report shows the cost of building convincing wallet malware collapsing while targeting stayed manual. The durable asset is the validated list, not the code.
Reality
- Evidence58
- Adoption32
- Hype gap+26
- Incentives62
- Confidence45