BlockThreat - Week 37, 2026
$11.6M stolen across 23 incidents. Mass phishing campaign targeting Trezor, BitBox, CoinTracking, and other projects.
Multiple data leaks this week. Customers of Trezor, BitBox, CoinTracking and other crypto projects were hit with phishing emails inviting them to download a fix for a "Critical Security Alert: STM32 Entropy Vulnerability". The common thread was Brevo, the email marketing platform, which had 138 of its accounts breached. Things are even wilder with Revolut, which simply handed over full customer details to a malicious actor posing as law enforcement. Embarrassing!
A reminder to consider all 3rd party dependencies including marketing platforms in your threat models and may be stop using platforms with multiple breaches.
In other news, Osmosis recently discovered that it was hacked again for more than two months ago for $3M. Oh and be sure to read the excellent article by Kudelski Group on various DPRK threat actors and their tactics.
Let’s dive into the news!