Check a Trezor Suite installer with GPG before you run it: the v26.9.2 filenames, the SatoshiLabs key fingerprint, and what a good signature cannot catch.
Yes, if it was strong and never leaked with the seed. The BIP-39 mechanism, which theft scenarios a Trezor passphrase survives, and the ones it does not.
Sender checks failed twice: mailing@trezor.io via Brevo, then help@trezor.io auto-replies. The checks that survive, in one table, plus Trezor's own rules.
The STM32 entropy alert is phishing sent through Trezor's breached Brevo account on 9 September. What BitBox and CoinTracking received, and what to do.
Two browser wallets that are not MetaMask, judged only on the seconds before you sign. One publishes its whole extension under MIT. The other bought the security team it was already using. What each vendor's own documents will and will not support.
Trezor aimed to have its Anonymous Delivery option live in the EU by September 2026. The company's own incident page still lists it as coming soon — and here is the narrow threat it would actually defend against.
Ledger published LSB 023, 024 and 025 on 27 August. The one with the widest reach sits in the Secure SDK rather than in any single app, and none of the three is repaired by updating device firmware.
Thousands of hardware wallet buyers had names, home addresses, phone numbers and emails taken in separate breaches at shipping partners, per TechCrunch. No key was touched, and the threat model changed anyway.
A peer-reviewed USENIX Security '26 paper reports that over 63% of EIP-7702 authorisation transactions are associated with malicious attacks on the accounts that signed them. What a delegation is, and why signing one is not the same as approving a token.