Labels

Lifestyle (433) Investing (391) Entertainment (303) Singapore (245) Technology (143) Rewards (131) Insights (107) Gaming (102) Equities (97) AI (87) Food (79) Data (77) U.S. (77) Crypto (71) Sports (68) Travel (63) Portfolio (54) News (47) Credit Card (37) Movies (35) Savings (34) Earnings (32) Football (32) Policies (27) Property (26) Shows (24) Holidays (23) Tennis (23) Bonds (16) Promotions (16) Toys (15) World (15) Malaysia (14) REITs (13) T-Bills (12) China (11) Apps (10) Healthcare (10) Referral (10) Anime (8) DeFi (8) Cash Management (7) Currency (7) Retirement (7) CPF (6) Security (6) ETFs (5) Miles (5) Shopping (5) Commodities (4) Robotics (4) Weird (4) platform (4) Cashback (3) Insurance (3) Japan (3) Blog (2) Reviews (2) Robo-Advisor (2) 1-For-1 (1) Asia (1) Australia (1) Banking (1) Funds Management (1) Futuristic (1) Indonesia (1) Inflation (1) Interesting (1) Nerfs (1) SGD (1) SSB (1) Social (1) Thailand (1)
Showing posts with label Security. Show all posts
Showing posts with label Security. Show all posts

Friday, 14 August 2026

Crypto Updates: Trezor Customer Data Exposed in Shipping Partner Breach


Source:



ChatGPT:


A data breach at ShipMonk, a third-party fulfilment partner used by Trezor, exposed personal information belonging to 13,689 Trezor customers. The incident affected customers who ordered between May 10 and August 8, 2026, across the US, UK, Sweden, Colombia, Brazil, Italy and Portugal. (Decrypt)

Of those affected, 11,742 customers had their full names, shipping addresses, phone numbers and email addresses exposed, while another 1,947 had their names, cities and email addresses leaked. Trezor says its own systems were not compromised and that wallets, private keys, recovery backups and devices remain secure. (Protos)

The bigger concern is what criminals can do with the information. Because the victims can now potentially be identified as Trezor customers—and, for most, their home addresses are known—the data could enable highly convincing phishing, impersonation and social-engineering attacks. The article also highlights the more serious possibility of physical targeting, noting that crypto-related “wrench attacks” have been increasing. (CryptoRank)

Trezor says its policy requiring fulfilment partners to delete or anonymise order data after 90 days limited the breach's scale. It is also accelerating an Anonymous Delivery option involving locker collection, neutral packaging, generic sender information and automatic deletion of shipping identifiers. The service is targeted for the EU by September and the US by year-end.

The incident comes shortly after the major Coldcard security crisis, making hardware-wallet users particularly nervous. However, the two incidents are fundamentally different: Trezor itself was not hacked, whereas the ShipMonk breach exposed customer information held by a logistics provider.

The main lesson is that even when a hardware wallet securely protects cryptocurrency, the purchase trail and customer's physical identity can remain a significant security vulnerability.

Social media & forum reaction

Reddit has the clearest and strongest reaction so far. A post in r/Bitcoin received about 310 upvotes, while Trezor's own Reddit announcement received about 308. (Reddit)

The dominant sentiment is essentially: “The wallet is safe, but the owner is now easier to target.”

One particularly useful Reddit discussion distinguishes the breach from an actual wallet hack: users emphasised that attackers did not obtain seed phrases, private keys or wallet access. (Reddit)

However, anxiety is still substantial. Users specifically worry about:

  • Targeted phishing using their real name and purchase history.

  • Criminals knowing their home address.

  • Potential physical attacks against wealthy crypto holders.

  • Trezor's reputation after Ledger previously suffered a customer-data breach.

  • Whether moving to another hardware-wallet manufacturer actually solves the underlying supply-chain/privacy problem. (Reddit)

There is also frustration from customers who recently bought Trezor specifically because of the recent Coldcard incident. Some commenters described the timing as particularly unfortunate, while others stressed that ShipMonk—not Trezor's wallet infrastructure—was breached. (Reddit)

Interestingly, users are also discussing Amazon purchases. Trezor representatives confirmed that orders from its official Amazon stores use a different fulfilment partner and were not affected. (Reddit)

r/CryptoCurrency reflects similar concerns, with users noting that the Coldcard incident may have pushed more people towards Trezor shortly before this breach. (Reddit)

HardwareZone: I couldn't find a meaningful current HardwareZone discussion specifically about this breach, so there isn't enough evidence to claim a Singapore-forum consensus.

X, Facebook, Instagram, TikTok and Threads: Publicly searchable discussion remains limited because posts are frequently login-gated or poorly indexed. I therefore wouldn't assign a sentiment percentage to these platforms.

Overall takeaway

This is not a Trezor wallet-security breach. It is a customer-privacy and physical-security breach—and arguably that distinction is the most important point.

For affected users, the realistic immediate threat is much more sophisticated phishing, not someone remotely emptying the Trezor. But because the leaked information can link a person's identity and home address to ownership of a hardware wallet, the incident is considerably more serious than an ordinary email database leak. (Financial Times)

Thursday, 11 September 2025

Technology Updates: Apple’s new iPhone 17 makes signing safer for frequent crypto users


Source:



ChatGPT:


Apple’s newly launched iPhone 17 introduces Memory Integrity Enforcement (MIE), a security upgrade designed to protect frequent crypto users from sophisticated cyberattacks. The system, enabled by default, applies Enhanced Memory Tagging Extension (EMTE)-style protections that detect and block unsafe memory access, such as out-of-bounds and use-after-free errors. These vulnerabilities account for nearly 70% of software flaws and are a common entry point for zero-day exploits targeting crypto wallets and Passkey approvals.

Cybersecurity firm Hacken highlighted that MIE “meaningfully” reduces risks by preventing attackers from hijacking signing code. By applying protections across both kernel and user-level processes, the system makes spyware and exploit development more difficult and expensive. Hacken noted that the feature directly benefits crypto wallet apps and Passkey flows, particularly for high-net-worth individuals or frequent signers.

Still, Apple’s MIE is not a cure-all. It does not address phishing, social engineering, malicious websites, or compromised applications. Users are urged to remain vigilant, as MIE complements but does not replace secure hardware wallets or basic security hygiene.

The upgrade comes amid rising threats to Apple’s crypto community. Just last month, a zero-click exploit was discovered that could compromise iPhones, iPads, and Macs without user interaction, prompting Apple to issue emergency patches. Earlier this year, Kaspersky reported malicious SDKs in app stores scanning photo galleries for wallet recovery phrases, while Trust Wallet previously warned users to disable iMessage due to an active zero-day threat.

By raising the difficulty and cost of attacks, iPhone 17’s MIE significantly improves baseline defenses for crypto users, but experts caution that layered security and user awareness remain essential.

Wednesday, 10 September 2025

Investing Updates: Ledger CTO warns users to halt onchain transactions amid massive NPM supply chain attack


Source:



ChatGPT:


Ledger’s Chief Technology Officer Charles Guillemet has urged crypto users to exercise extreme caution following what experts describe as one of the largest supply chain attacks in history. The incident stems from the compromise of an NPM account belonging to a reputable developer, with malicious code embedded in popular JavaScript packages that collectively have been downloaded more than one billion times.

Guillemet explained that the injected code silently swaps cryptocurrency addresses, redirecting funds to attackers without user awareness. This method, he warned, could endanger countless websites and applications — including crypto projects that rely heavily on JavaScript dependencies. Developers such as @0xCygaar and @0x_ultra highlighted that widely used packages like Chalk and its dependencies were impacted, noting billions of weekly downloads.

While the packages were reportedly patched around 15:15 UTC and NPM has disabled compromised versions, concerns remain that some website frontends could still be vulnerable. The package maintainer confirmed their account was hijacked after receiving a phishing email impersonating npmjs.com. Attackers threatened account lockouts to pressure maintainers into clicking malicious links.

Guillemet emphasized that users of hardware wallets like Ledger with “clear signing” are safe, provided they verify each transaction before approval. Those relying solely on software wallets are advised to halt onchain transactions temporarily.

The attack recalls earlier high-profile thefts, such as the $1.5 billion drained from Bybit by North Korean hackers, underscoring the crypto industry’s ongoing exposure to sophisticated exploits. Developers are urged to audit dependencies immediately and ensure their applications have not pulled compromised updates.

Though mitigations are underway, security experts caution that vigilance is crucial until the full extent of the attack is confirmed.

Saturday, 15 March 2025

Technology Updates : Hardware wallet Ledger helps competitor Trezor resolve security vulnerability


Source : 



Apple Intelligence : 


Security Flaw Discovered: Ledger’s open-source research arm discovered a security vulnerability in Trezor’s Safe 3 and 5 models.


Vulnerability Details: Cryptographic operations could be performed on the microcontroller, potentially making the devices vulnerable to advanced attacks.


Patch Implemented: Trezor has patched the vulnerability, addressing the security flaw found by Ledger.


Trezor Security Issue: Ledger demonstrated a vulnerability in Trezor’s firmware integrity check, allowing attackers to bypass it.


Trezor’s Response: Trezor confirmed the issue was resolved but didn’t disclose the method used. They also stated that user funds remained safe and no action was required.


Ledger’s Security Breaches: Ledger has also faced security breaches, including a hacker stealing $484,000 worth of crypto assets in December 2023 and another threat actor publishing the mailing addresses of 270,000 customers in June 2020.

Saturday, 11 January 2025

Investing Updates: Polymarket Blocked in Singapore: Prediction Market Faces Fresh Scrutiny


URLhttps://www.blockhead.co/2025/01/07/polymarket-blocked-in-singapore-prediction-market-faces-fresh-scrutiny/

Gemini Summarized:
  • Polymarket Blocked: The Singapore Police Force has blocked Polymarket, a prediction market platform, labeling it an "illegal gambling site."
  • Regulatory Crackdown: This action comes amidst a crackdown on unlicensed gambling platforms in Singapore.
  • Enforcement Shift: The Singapore Police Force now oversees enforcement, previously handled by the Gambling Regulatory Authority (GRA).
  • Polymarket's Model: Polymarket allows users to bet on world events using cryptocurrency. It has faced regulatory challenges before, including a settlement with the U.S. Commodity Futures Trading Commission.
  • Regulatory Concerns: The Singapore ban raises questions about the distinction between prediction markets and gambling.
  • Broader Implications: This case highlights the challenges of regulating blockchain-based platforms and the evolving regulatory landscape for prediction markets globally.

Saturday, 19 October 2024

Technology Updates : Passkeys

URL: https://9to5mac.com/2024/10/14/new-passkeys-import-export/

OpenAI:

Here are the 5 key points from the article on 9to5Mac about new passkey import/export specifications:

  • New Specifications: The FIDO Alliance has introduced new specifications allowing users to import and export passkeys.
  • User Choice: The new features aim to promote user choice by enabling passkey transfers between different password managers.
  • Current Limitations: Currently, there is no secure way to move passkeys between password managers like Apple's Passwords app and 1Password.
  • Credential Exchange Protocol: The draft specifications establish the Credential Exchange Protocol (CXP) and Credential Exchange Format (CXF) for transferring passkeys.
  • Enhanced Security: The new specifications ensure that passkeys can be transferred while maintaining encryption.

My Thoughts:


This is an important development in IT security.


Need a seamless way to port passwords securely with so many things in life being digitally dependent.