{"data":[{"id":"trezor-brevo-newsletter-2026","service_slug":"trezor","title":"Brevo newsletter export and fraudulent STM32 email","type":"breach","severity":"high","status":"ongoing","corroboration":"reported","date":"2026-09-09","discovered_date":"2026-09-09","summary":"Trezor's September 17, 2026 update reports 347,149 newsletter email addresses exported through Brevo. The September 9 message headed 'Critical Security Alert: STM32 Entropy Vulnerability' was phishing: its app requested a wallet backup, not a genuine hardware repair. Trezor says no product, wallet or account system was affected and no passwords or wallet data were held in this list. Brevo says the messages passed email authentication, and attacker access is closed; active here means residual phishing exposure. Do not follow the email links or disclose a backup; delete the message. If a backup was entered, Trezor directs an immediate transfer to a new wallet using its official guide. A firmware update does not undo contact-data exposure. Sources checked September 21, 2026.","user_impact":"Continuing targeted phishing from exported emails. No verified loss-of-funds total in the reviewed disclosures. A convincing sender does not authenticate a request for a wallet backup.","status_note":"Date follows Trezor's September 9 incident account; Brevo dates detection to September 10 at 06:30 UTC and closure of the entry route to 08:30 UTC. These are attributed milestones, not a reconciled forensic start time. Brevo says access was closed and sessions reset; Trezor suspended its account and disabled links. Ongoing denotes residual exported-data/phishing exposure, not continuing attacker access or a hardware vulnerability. Brevo's postmortem describes a permanent fix as being deployed, not independently verified here. Corroboration remains reported: the two affected companies' accounts were reviewed, not an independent forensic audit.","article_url":null,"service_url":"https://cunicula.com/en/provider/trezor","incident_url":"https://cunicula.com/en/incidents#trezor-brevo-newsletter-2026","sources":[{"label":"Trezor disclosure, updated September 17, 2026","url":"https://trezor.io/blog/news/security-incident-at-brevo-our-third-party-email-provider","publisher":"Trezor","date":"2026-09-17","basis":"primary"},{"label":"Brevo September 10 postmortem","url":"https://status.brevo.com/incidents/01M266V1CZKJQNGZRNEGFD5CQE/write-up","publisher":"Brevo","date":"2026-09-10","basis":"primary"},{"label":"Trezor: moving funds after backup exposure (checked September 21)","url":"https://trezor.io/guides/backups-recovery/general-standards/move-crypto-to-a-wallet-with-a-new-wallet-backup","publisher":"Trezor","date":"2026-09-21","basis":"primary"}],"reviewed_at":"2026-09-21"},{"id":"simsup-tor-route-degradation-2026-08","service_slug":"simsup","title":"Simsup private-network storefront route degradation","type":"outage","severity":"low","status":"resolved","corroboration":"reported","date":"2026-08-25","discovered_date":"2026-08-25","summary":"The prior review recorded an unreliable Tor route. The current status page reports the storefront, payments and served private-network routes operational; one recent I2P payment check failed but no ongoing service outage is reported.","user_impact":"The prior review recorded an unreliable Tor route. The current status page reports the storefront, payments and served private-network routes operational; one recent I2P payment check failed but no ongoing service outage is reported.","status_note":"The reviewed record marks this incident resolved; remediation is complete. Independent corroboration was not established in the reviewed source set.","article_url":null,"service_url":"https://cunicula.com/en/provider/simsup","incident_url":"https://cunicula.com/en/incidents#simsup-tor-route-degradation-2026-08","sources":[{"label":"Simsup status","url":"https://status.simsup.com/","publisher":"status.simsup.com","date":"2026-08-25","basis":"primary"}],"reviewed_at":"2026-08-27"},{"id":"btcpay-server-2026-08-24-this-is-a-security-release-updating-is-recommended-for-servers-shared-w","service_slug":"btcpay-server","title":"This is a security release; updating is recommended for servers shared with many users.","type":"shutdown","severity":"medium","status":"ongoing","corroboration":"reported","date":"2026-08-24","discovered_date":"2026-08-24","summary":"Upgrade to v2.4.3 or later, especially on shared multi-user servers; the release does not claim a confirmed compromise.","user_impact":"Upgrade to v2.4.3 or later, especially on shared multi-user servers; the release does not claim a confirmed compromise.","status_note":"The reviewed record does not establish full resolution; remediation is unknown. Independent corroboration was not established in the reviewed source set.","article_url":null,"service_url":"https://cunicula.com/en/provider/btcpay-server","incident_url":"https://cunicula.com/en/incidents#btcpay-server-2026-08-24-this-is-a-security-release-updating-is-recommended-for-servers-shared-w","sources":[{"label":"This is a security release; updating is recommended for servers shared with many users.","url":"https://github.com/btcpayserver/btcpayserver/releases/tag/v2.4.3","publisher":"github.com","date":"2026-08-24","basis":"primary"}],"reviewed_at":"2026-08-27"},{"id":"sageswap-support-impersonation-2026","service_slug":"sageswap","title":"Support impersonation and phishing campaign targeting SageSwap users","type":"breach","severity":"medium","status":"ongoing","corroboration":"reported","date":"2026-08-24","discovered_date":"2026-08-24","summary":"SageSwap reports an active campaign impersonating its support across Telegram and platform accounts and warns that support will never request wallet connection or wallet information. No resolution notice was found.","user_impact":"SageSwap reports an active campaign impersonating its support across Telegram and platform accounts and warns that support will never request wallet connection or wallet information. No resolution notice was found.","status_note":"The reviewed record does not establish full resolution; remediation is unresolved. Independent corroboration was not established in the reviewed source set.","article_url":null,"service_url":"https://cunicula.com/en/provider/sageswap","incident_url":"https://cunicula.com/en/incidents#sageswap-support-impersonation-2026","sources":[{"label":"SageSwap official warning","url":"https://x.com/SageSwap_io/status/2091830071778562151","publisher":"x.com","date":"2026-08-24","basis":"primary"}],"reviewed_at":"2026-08-27"},{"id":"pikasim-network-connectivity-2026-08-21-0331","service_slug":"pikasim","title":"PikaSIM network connectivity interruption (03:31 UTC)","type":"outage","severity":"low","status":"resolved","corroboration":"reported","date":"2026-08-21","discovered_date":"2026-08-21","summary":"The current official status history records a resolved network-connectivity issue at 03:31 UTC on 21 August 2026; no data or asset compromise is claimed.","user_impact":"The current official status history records a resolved network-connectivity issue at 03:31 UTC on 21 August 2026; no data or asset compromise is claimed.","status_note":"The reviewed record marks this incident resolved; remediation is complete. Independent corroboration was not established in the reviewed source set.","article_url":null,"service_url":"https://cunicula.com/en/provider/pikasim","incident_url":"https://cunicula.com/en/incidents#pikasim-network-connectivity-2026-08-21-0331","sources":[{"label":"PikaSIM network status","url":"https://pikasim.com/status","publisher":"pikasim.com","date":"2026-08-21","basis":"primary"}],"reviewed_at":"2026-08-27"},{"id":"pikasim-network-connectivity-2026-08-21-0515","service_slug":"pikasim","title":"PikaSIM network connectivity interruption (05:15 UTC)","type":"outage","severity":"low","status":"resolved","corroboration":"reported","date":"2026-08-21","discovered_date":"2026-08-21","summary":"The current official status history records a second resolved network-connectivity issue at 05:15 UTC on 21 August 2026; no data or asset compromise is claimed.","user_impact":"The current official status history records a second resolved network-connectivity issue at 05:15 UTC on 21 August 2026; no data or asset compromise is claimed.","status_note":"The reviewed record marks this incident resolved; remediation is complete. Independent corroboration was not established in the reviewed source set.","article_url":null,"service_url":"https://cunicula.com/en/provider/pikasim","incident_url":"https://cunicula.com/en/incidents#pikasim-network-connectivity-2026-08-21-0515","sources":[{"label":"PikaSIM network status","url":"https://pikasim.com/status","publisher":"pikasim.com","date":"2026-08-21","basis":"primary"}],"reviewed_at":"2026-08-27"},{"id":"robosats-python-ci-pr-head-rce-2026","service_slug":"robosats","title":"Python CI workflow allowed pull-request code execution","type":"vulnerability","severity":"high","status":"resolved","corroboration":"reported","date":"2026-08-20","discovered_date":"2026-08-20","summary":"GHSA-rxx8-rv5g-wpch describes a high-severity pull_request_target workflow flaw through 0.8.5-alpha. RoboSats identifies 0.8.6-alpha as patched and that release was already current when the advisory was published.","user_impact":"GHSA-rxx8-rv5g-wpch describes a high-severity pull_request_target workflow flaw through 0.8.5-alpha. RoboSats identifies 0.8.6-alpha as patched and that release was already current when the advisory was published.","status_note":"The reviewed record marks this incident resolved; remediation is complete. Independent corroboration was not established in the reviewed source set.","article_url":null,"service_url":"https://cunicula.com/en/provider/robosats","incident_url":"https://cunicula.com/en/incidents#robosats-python-ci-pr-head-rce-2026","sources":[{"label":"RoboSats GHSA-rxx8-rv5g-wpch","url":"https://github.com/RoboSats/robosats/security/advisories/GHSA-rxx8-rv5g-wpch","publisher":"github.com","date":"2026-08-20","basis":"primary"},{"label":"Current latest RoboSats release","url":"https://github.com/RoboSats/robosats/releases/latest","publisher":"github.com","date":"2026-08-20","basis":"primary"}],"reviewed_at":"2026-08-27"},{"id":"robosats-javascript-ci-pr-head-rce-2026","service_slug":"robosats","title":"JavaScript CI workflow allowed pull-request code execution","type":"vulnerability","severity":"high","status":"resolved","corroboration":"reported","date":"2026-08-20","discovered_date":"2026-08-20","summary":"GHSA-xjwx-6j4q-hrr6 describes high-severity arbitrary runner-code execution through 0.8.5. RoboSats identifies 0.8.6 as patched and that release was already current when the advisory was published.","user_impact":"GHSA-xjwx-6j4q-hrr6 describes high-severity arbitrary runner-code execution through 0.8.5. RoboSats identifies 0.8.6 as patched and that release was already current when the advisory was published.","status_note":"The reviewed record marks this incident resolved; remediation is complete. Independent corroboration was not established in the reviewed source set.","article_url":null,"service_url":"https://cunicula.com/en/provider/robosats","incident_url":"https://cunicula.com/en/incidents#robosats-javascript-ci-pr-head-rce-2026","sources":[{"label":"RoboSats GHSA-xjwx-6j4q-hrr6","url":"https://github.com/RoboSats/robosats/security/advisories/GHSA-xjwx-6j4q-hrr6","publisher":"github.com","date":"2026-08-20","basis":"primary"},{"label":"Current latest RoboSats release","url":"https://github.com/RoboSats/robosats/releases/latest","publisher":"github.com","date":"2026-08-20","basis":"primary"}],"reviewed_at":"2026-08-27"},{"id":"robosats-coordinator-notice-xss-2026","service_slug":"robosats","title":"Coordinator notice raw HTML permits JavaScript execution","type":"vulnerability","severity":"medium","status":"unpatched","corroboration":"reported","date":"2026-08-20","discovered_date":"2026-08-20","summary":"RoboSats published GHSA-p353-f8m7-8v95: coordinator notice HTML can execute JavaScript and expose robot root credentials across coordinators. Versions through 0.8.6-alpha are affected; 0.8.7-alpha is the patched line, while the current latest release is 0.8.6-alpha.","user_impact":"RoboSats published GHSA-p353-f8m7-8v95: coordinator notice HTML can execute JavaScript and expose robot root credentials across coordinators. Versions through 0.8.6-alpha are affected; 0.8.7-alpha is the patched line, while the current latest release is 0.8.6-alpha.","status_note":"The reviewed record does not establish full resolution; remediation is partial. Independent corroboration was not established in the reviewed source set.","article_url":null,"service_url":"https://cunicula.com/en/provider/robosats","incident_url":"https://cunicula.com/en/incidents#robosats-coordinator-notice-xss-2026","sources":[{"label":"RoboSats GHSA-p353-f8m7-8v95","url":"https://github.com/RoboSats/robosats/security/advisories/GHSA-p353-f8m7-8v95","publisher":"github.com","date":"2026-08-20","basis":"primary"},{"label":"Current latest RoboSats release","url":"https://github.com/RoboSats/robosats/releases/latest","publisher":"github.com","date":"2026-08-20","basis":"primary"}],"reviewed_at":"2026-08-27"},{"id":"robosats-private-order-api-disclosure-2026","service_slug":"robosats","title":"Private orders exposed through unauthenticated API filters","type":"vulnerability","severity":"medium","status":"unpatched","corroboration":"reported","date":"2026-08-20","discovered_date":"2026-08-20","summary":"RoboSats published GHSA-r6f6-x59j-8q69: password-protected orders can be returned without authentication, including payment method, amount, maker nickname and face-to-face coordinates. Versions through 0.8.6-alpha are affected; 0.8.7-alpha is the patched line, while the current latest release is 0.8.6-alpha.","user_impact":"RoboSats published GHSA-r6f6-x59j-8q69: password-protected orders can be returned without authentication, including payment method, amount, maker nickname and face-to-face coordinates. Versions through 0.8.6-alpha are affected; 0.8.7-alpha is the patched line, while the current latest release is 0.8.6-alpha.","status_note":"The reviewed record does not establish full resolution; remediation is partial. Independent corroboration was not established in the reviewed source set.","article_url":null,"service_url":"https://cunicula.com/en/provider/robosats","incident_url":"https://cunicula.com/en/incidents#robosats-private-order-api-disclosure-2026","sources":[{"label":"RoboSats GHSA-r6f6-x59j-8q69","url":"https://github.com/RoboSats/robosats/security/advisories/GHSA-r6f6-x59j-8q69","publisher":"github.com","date":"2026-08-20","basis":"primary"},{"label":"Current latest RoboSats release","url":"https://github.com/RoboSats/robosats/releases/latest","publisher":"github.com","date":"2026-08-20","basis":"primary"}],"reviewed_at":"2026-08-27"},{"id":"robosats-reward-double-withdrawal-2026","service_slug":"robosats","title":"Concurrent reward withdrawals could drain coordinator funds","type":"vulnerability","severity":"medium","status":"resolved","corroboration":"reported","date":"2026-08-20","discovered_date":"2026-08-20","summary":"GHSA-vp6p-w2r2-jj2v describes a reward-withdrawal race condition affecting versions through 0.8.5-alpha. RoboSats identifies 0.8.6-alpha as patched and that release was already current when the advisory was published.","user_impact":"GHSA-vp6p-w2r2-jj2v describes a reward-withdrawal race condition affecting versions through 0.8.5-alpha. RoboSats identifies 0.8.6-alpha as patched and that release was already current when the advisory was published.","status_note":"The reviewed record marks this incident resolved; remediation is complete. Independent corroboration was not established in the reviewed source set.","article_url":null,"service_url":"https://cunicula.com/en/provider/robosats","incident_url":"https://cunicula.com/en/incidents#robosats-reward-double-withdrawal-2026","sources":[{"label":"RoboSats GHSA-vp6p-w2r2-jj2v","url":"https://github.com/RoboSats/robosats/security/advisories/GHSA-vp6p-w2r2-jj2v","publisher":"github.com","date":"2026-08-20","basis":"primary"},{"label":"Current latest RoboSats release","url":"https://github.com/RoboSats/robosats/releases/latest","publisher":"github.com","date":"2026-08-20","basis":"primary"}],"reviewed_at":"2026-08-27"},{"id":"boltz-2026-08-12-service-suspension-and-ownership-handover-after-","service_slug":"boltz","title":"Service suspension and ownership handover after targeted attacks","type":"shutdown","severity":"high","status":"disputed","corroboration":"reported","date":"2026-08-12","discovered_date":"2026-08-12","summary":"Boltz said AI-assisted attackers had targeted the service, suspended operations, and announced that all original founders stepped down. On 18 August the old crew still controlled the service and the handover remained in progress; no later provider-owned completion notice was found in the review window.","user_impact":"Boltz said AI-assisted attackers had targeted the service, suspended operations, and announced that all original founders stepped down. On 18 August the old crew still controlled the service and the handover remained in progress; no later provider-owned completion notice was found in the review window.","status_note":"Current review records this incident as monitoring; remediation is unresolved. Corroboration remains reported because fewer than two independent publishers were reviewed.","article_url":null,"service_url":"https://cunicula.com/en/provider/boltz","incident_url":"https://cunicula.com/en/incidents#boltz-2026-08-12-service-suspension-and-ownership-handover-after-","sources":[{"label":"Boltz suspension and founder departure","url":"https://x.com/Boltzhq/status/2087636521746674168","publisher":"x.com","date":"2026-08-12","basis":"primary"},{"label":"Boltz handover still in progress","url":"https://x.com/Boltzhq/status/2089675696494834097","publisher":"x.com","date":"2026-08-12","basis":"primary"}],"reviewed_at":"2026-08-25"},{"id":"trezor-shipmonk-order-data-2026","service_slug":"trezor","title":"ShipMonk shipping data and historical-order exposure","type":"breach","severity":"high","status":"ongoing","corroboration":"reported","date":"2026-08-10","discovered_date":"2026-08-10","summary":"Trezor's September 4, 2026 update reports 80,689 affected customers in the ShipMonk incident, including approximately 67,000 additional US customers with November 2019 to August 2021 orders. Exposed fields include names, emails, phone numbers, shipping addresses and order numbers; 1,947 customers had partial name/city/email exposure. Trezor says old data remained despite written deletion assurances, its own systems and devices were not compromised, and ShipMonk secured its systems. Active here means residual data exposure, not a continuing intrusion. Address exposure can support fraudulent calls, letters and physical targeting; accurate order details do not authenticate a message. Never share a wallet backup and verify communications through the official site. This population may overlap with Brevo's contacts: do not add the totals. Sources checked September 21, 2026.","user_impact":"Customer identity and address exposure, not a reported wallet-key leak. Trezor says parcel contents were not exposed. Phishing and potential physical-security risks persist after the supplier closes access; no specific physical attack is established by these disclosures.","status_note":"August 10 is ShipMonk's notification date to Trezor; the intrusion start is not disclosed. Page header says August 12, while the body labels the original article August 13. Trezor learned of the historical-data expansion September 2 and updated the notice September 4. Trezor says ShipMonk secured and hardened affected systems and customers were notified. Ongoing denotes unrecalled customer-data exposure, not confirmed continuing intrusion. Corroboration remains reported: only Trezor's disclosure was obtained, with no separate public ShipMonk forensic account located. Anonymous Delivery remains described as coming soon in the reviewed notice, not verified available.","article_url":null,"service_url":"https://cunicula.com/en/provider/trezor","incident_url":"https://cunicula.com/en/incidents#trezor-shipmonk-order-data-2026","sources":[{"label":"Trezor ShipMonk disclosure, updated September 4, 2026","url":"https://trezor.io/blog/news/recent-customer-data-exposed-in-shipping-provider-incident","publisher":"Trezor","date":"2026-09-04","basis":"primary"}],"reviewed_at":"2026-09-21"},{"id":"ivpn-2026-08-07-btcpay-and-lightning-payment-server-compromise","service_slug":"ivpn","title":"BTCPay and Lightning payment-server compromise","type":"breach","severity":"high","status":"resolved","corroboration":"reported","date":"2026-08-07","discovered_date":"2026-08-07","summary":"A critical BTCPay Server vulnerability exposed Lightning-node credentials and 0.6168 BTC of IVPN operating funds was stolen; IVPN reported no customer data or funds and no VPN infrastructure impact.","user_impact":"A critical BTCPay Server vulnerability exposed Lightning-node credentials and 0.6168 BTC of IVPN operating funds was stolen; IVPN reported no customer data or funds and no VPN infrastructure impact.","status_note":"The reviewed record marks this incident resolved; remediation is complete. Independent corroboration was not established in the reviewed source set.","article_url":null,"service_url":"https://cunicula.com/en/provider/ivpn","incident_url":"https://cunicula.com/en/incidents#ivpn-2026-08-07-btcpay-and-lightning-payment-server-compromise","sources":[{"label":"IVPN incident disclosure (now 404; hash-locked 2026-08-25 capture)","url":"https://www.ivpn.net/en/blog/security-incident-bitcoin-payment-server/","publisher":"www.ivpn.net","date":"2026-08-07","basis":"primary"}],"reviewed_at":"2026-08-27"},{"id":"basicswap-2026-08-01-adaptor-signature-counterparty-fund-trapping-iss","service_slug":"basicswap","title":"Adaptor-signature counterparty fund-trapping issue","type":"breach","severity":"critical","status":"resolved","corroboration":"reported","date":"2026-08-01","discovered_date":"2026-08-01","summary":"BasicSwap described a critical adaptor-signature issue that could let a counterparty trap, but not steal, swap funds. Version 0.17.7 fixed it; the project then published mandatory Bitcoin Cash/Litecoin follow-up releases 0.17.8 and 0.17.9 on 3 August.","user_impact":"BasicSwap described a critical adaptor-signature issue that could let a counterparty trap, but not steal, swap funds. Version 0.17.7 fixed it; the project then published mandatory Bitcoin Cash/Litecoin follow-up releases 0.17.8 and 0.17.9 on 3 August.","status_note":"Current review records this incident as resolved; remediation is complete. Corroboration remains reported because fewer than two independent publishers were reviewed.","article_url":null,"service_url":"https://cunicula.com/en/provider/basicswap","incident_url":"https://cunicula.com/en/incidents#basicswap-2026-08-01-adaptor-signature-counterparty-fund-trapping-iss","sources":[{"label":"BasicSwap v0.17.7 mandatory release","url":"https://x.com/BasicSwapDEX/status/2083562003356930454","publisher":"x.com","date":"2026-08-01","basis":"primary"},{"label":"BasicSwap v0.17.8/v0.17.9 follow-up","url":"https://x.com/BasicSwapDEX/status/2084076112179609945","publisher":"x.com","date":"2026-08-01","basis":"primary"}],"reviewed_at":"2026-08-25"},{"id":"coldcard-firmware-rng-entropy-2026","service_slug":"coldcard","title":"2021-2026 firmware RNG entropy defect and Bitcoin theft","type":"vulnerability","severity":"critical","status":"unpatched","corroboration":"confirmed","date":"2026-07-30","discovered_date":"2026-07-30","summary":"Affected firmware could generate wallet seeds through a deterministic software fallback rather than the hardware RNG. Affected releases include Mk2 and Mk3 4.0.1 through 4.1.9, Mk4 and Mk5 before 5.6.0, Q before 1.5.0Q, and Edge before 6.6.0X or 6.6.0QX. Current recommended standard releases are Mk4 and Mk5 5.6.2 and Q 1.5.2Q. Updating firmware prevents newly affected seeds but does not repair an existing affected seed. A BIP-39 passphrase does not repair the seed; users must migrate under the official guidance unless its exact independent-dice condition applies. The formal technical postmortem remains unpublished.","user_impact":"Users whose seeds were generated on affected firmware remain at risk after updating. They must generate a new seed on fixed firmware and move funds unless the documented independent-dice exception applies. A strong BIP-39 passphrase does not repair the affected seed. Coinkite has acknowledged theft and severe losses; third-party loss totals remain disputed.","status_note":"The incident remains unpatched for users with unmigrated affected seeds. Current firmware fixes new seed generation but cannot repair seeds already created.","article_url":"https://cunicula.com/en/articles/coldcard-rng-entropy-incident-2026","service_url":"https://cunicula.com/en/provider/coldcard","incident_url":"https://cunicula.com/en/incidents#coldcard-firmware-rng-entropy-2026","sources":[{"label":"Coinkite security advisory","url":"https://blog.coinkite.com/coldcard-mk3-seed-generation-warning/","publisher":"Coinkite","date":"2026-07-30","basis":"primary"},{"label":"Coinkite technical backgrounder","url":"https://blog.coinkite.com/entropy-technical-backgrounder/","publisher":"Coinkite","date":"2026-07-30","basis":"primary"},{"label":"Coldcard firmware changelog","url":"https://github.com/Coldcard/firmware/blob/master/releases/ChangeLog.md","publisher":"Coinkite","date":"2026-07-30","basis":"primary"},{"label":"Block Engineering independent analysis","url":"https://engineering.block.xyz/blog/predictable-rng-fallback-and-32-bit-reseed-in-coldcard-firmware","publisher":"engineering.block.xyz","date":"2026-07-30","basis":"independent-analysis"},{"label":"COLDCARD current security status and release guidance","url":"https://coldcard.com/security/status","publisher":"Coinkite","date":"2026-09-04","basis":"primary"},{"label":"COLDCARD affected-seed migration guide","url":"https://coldcard.com/security/migrate","publisher":"Coinkite","date":"2026-09-04","basis":"primary"}],"reviewed_at":"2026-09-05"},{"id":"incognet-2026-07-19-kansas-city-network-ddos-event","service_slug":"incognet","title":"Kansas City network DDoS event","type":"outage","severity":"high","status":"ongoing","corroboration":"reported","date":"2026-07-19","discovered_date":"2026-07-19","summary":"Official status reporting identified a DDoS event affecting the Kansas City network; current first-party status content does not establish resolution.","user_impact":"Official status reporting identified a DDoS event affecting the Kansas City network; current first-party status content does not establish resolution.","status_note":"The reviewed record does not establish full resolution; remediation is unresolved. Independent corroboration was not established in the reviewed source set.","article_url":null,"service_url":"https://cunicula.com/en/provider/incognet","incident_url":"https://cunicula.com/en/incidents#incognet-2026-07-19-kansas-city-network-ddos-event","sources":[{"label":"IncogNET status","url":"https://portal.incognet.io/serverstatus.php","publisher":"portal.incognet.io","date":"2026-07-19","basis":"primary"}],"reviewed_at":"2026-08-27"},{"id":"basicswap-2026-07-14-july-2026-swap-security-issue","service_slug":"basicswap","title":"July 2026 swap-security issue","type":"breach","severity":"high","status":"resolved","corroboration":"reported","date":"2026-07-14","discovered_date":"2026-07-14","summary":"BasicSwap told users to withdraw offers and stop new swaps while a swap-security issue was fixed. Version 0.17.2 was published the same day as the mandatory fix.","user_impact":"BasicSwap told users to withdraw offers and stop new swaps while a swap-security issue was fixed. Version 0.17.2 was published the same day as the mandatory fix.","status_note":"Current review records this incident as resolved; remediation is complete. Corroboration remains reported because fewer than two independent publishers were reviewed.","article_url":null,"service_url":"https://cunicula.com/en/provider/basicswap","incident_url":"https://cunicula.com/en/incidents#basicswap-2026-07-14-july-2026-swap-security-issue","sources":[{"label":"BasicSwap initial security notice","url":"https://x.com/BasicSwapDEX/status/2076894892786143518","publisher":"x.com","date":"2026-07-14","basis":"primary"},{"label":"BasicSwap v0.17.2 fix","url":"https://x.com/BasicSwapDEX/status/2077030033273561112","publisher":"x.com","date":"2026-07-14","basis":"primary"}],"reviewed_at":"2026-08-25"},{"id":"quad9-2026-06-29-quad9-net-website-short-outage","service_slug":"quad9","title":"Quad9.net website short outage","type":"outage","severity":"low","status":"resolved","corroboration":"reported","date":"2026-06-29","discovered_date":"2026-06-29","summary":"Quad9's main website was unavailable for four minutes; the official status page says all DNS nodes/services remained unaffected.","user_impact":"Quad9's main website was unavailable for four minutes; the official status page says all DNS nodes/services remained unaffected.","status_note":"Current review records this incident as resolved; remediation is complete. Corroboration remains reported because fewer than two independent publishers were reviewed.","article_url":null,"service_url":"https://cunicula.com/en/provider/quad9","incident_url":"https://cunicula.com/en/incidents#quad9-2026-06-29-quad9-net-website-short-outage","sources":[{"label":"Quad9 official incident history","url":"https://uptime.quad9.net/incidents","publisher":"uptime.quad9.net","date":"2026-06-29","basis":"primary"}],"reviewed_at":"2026-08-25"},{"id":"retoswap-2026-06-16-haveno-trade-protocol-exploit-and-trading-halt","service_slug":"retoswap","title":"Haveno trade-protocol exploit and trading halt","type":"breach","severity":"high","status":"resolved","corroboration":"reported","date":"2026-06-16","discovered_date":"2026-06-16","summary":"RetoSwap halted trading after reporting that the Haveno trade protocol was being actively exploited. It resumed on 23 June with v1.8.0 and said it was coordinating recovery with affected users.","user_impact":"RetoSwap halted trading after reporting that the Haveno trade protocol was being actively exploited. It resumed on 23 June with v1.8.0 and said it was coordinating recovery with affected users.","status_note":"Current review records this incident as resolved; remediation is complete. Corroboration remains reported because fewer than two independent publishers were reviewed.","article_url":null,"service_url":"https://cunicula.com/en/provider/retoswap","incident_url":"https://cunicula.com/en/incidents#retoswap-2026-06-16-haveno-trade-protocol-exploit-and-trading-halt","sources":[{"label":"RetoSwap exploit notice","url":"https://x.com/RetoSwap/status/2066960238545162410","publisher":"x.com","date":"2026-06-23","basis":"primary"},{"label":"RetoSwap trading-halt notice","url":"https://x.com/RetoSwap/status/2066960247235735614","publisher":"x.com","date":"2026-06-23","basis":"primary"},{"label":"RetoSwap recovery notice","url":"https://x.com/RetoSwap/status/2069472096644653110","publisher":"x.com","date":"2026-06-23","basis":"primary"},{"label":"RetoSwap v1.8.0 notice","url":"https://x.com/RetoSwap/status/2069472807646367875","publisher":"x.com","date":"2026-06-23","basis":"primary"}],"reviewed_at":"2026-08-25"},{"id":"solvocard-card-program-ended-2026","service_slug":"solvocard","title":"Card program ended with refunds still reported unpaid","type":"shutdown","severity":"high","status":"ongoing","corroboration":"reported","date":"2026-06-10","discovered_date":"2026-08-05","summary":"KYCnot.me reports that the Mastercard program ended in June 2026. It records multiple users awaiting balance refunds and says its own residual test balance remained unpaid at the last review. SolvoCard's public site did not show an incident notice in the 5 Aug 2026 review.","user_impact":"A user holding a balance when the program ended may not be able to retrieve it. SolvoCard's public site carried no incident notice at the 5 Aug 2026 review, so a prospective user reading only the operator's own pages would not learn that the program had ended.","status_note":"Recorded as ongoing because no source read for this row shows the outstanding balances settled. Corroboration is reported, not confirmed: this rests on one reviewer's account, and searches for a second independent account returned nothing usable at the 7 Aug 2026 review.","article_url":null,"service_url":"https://cunicula.com/en/provider/solvocard","incident_url":"https://cunicula.com/en/incidents#solvocard-card-program-ended-2026","sources":[{"label":"KYCnot.me SolvoCard record","url":"https://kycnot.me/service/solvocardcom","publisher":"kycnot.me","date":"2026-06-10","basis":"third-party-review"}],"reviewed_at":"2026-08-05"},{"id":"bisq-2026-05-01-security-incident-post-mortem","service_slug":"bisq","title":"Security Incident Post-Mortem","type":"breach","severity":"high","status":"ongoing","corroboration":"reported","date":"2026-05-01","discovered_date":"2026-05-01","summary":"Require current patched releases, preserve the May 1, 2026 incident, and reassess after a complete audit report and remediation record are published.","user_impact":"Require current patched releases, preserve the May 1, 2026 incident, and reassess after a complete audit report and remediation record are published.","status_note":"The reviewed record does not establish full resolution; remediation is unknown. Independent corroboration was not established in the reviewed source set.","article_url":null,"service_url":"https://cunicula.com/en/provider/bisq","incident_url":"https://cunicula.com/en/incidents#bisq-2026-05-01-security-incident-post-mortem","sources":[{"label":"Security Incident Post-Mortem","url":"https://bisq.network/blog/security-incident-post-mortem/","publisher":"bisq.network","date":"2026-05-01","basis":"primary"}],"reviewed_at":"2026-08-27"},{"id":"flexa-2026-03-31-spedn-consumer-app-shutdown","service_slug":"flexa","title":"SPEDN consumer app shutdown","type":"shutdown","severity":"medium","status":"resolved","corroboration":"reported","date":"2026-03-31","discovered_date":"2026-03-31","summary":"Flexa shut down the SPEDN proof-of-concept consumer app. The broader Flexa payment/money-movement infrastructure continued, changed leadership in June, and announced availability across 37 SEPA countries and territories in July.","user_impact":"Flexa shut down the SPEDN proof-of-concept consumer app. The broader Flexa payment/money-movement infrastructure continued, changed leadership in June, and announced availability across 37 SEPA countries and territories in July.","status_note":"Current review records this incident as resolved; remediation is complete. Corroboration remains reported because fewer than two independent publishers were reviewed.","article_url":null,"service_url":"https://cunicula.com/en/provider/flexa","incident_url":"https://cunicula.com/en/incidents#flexa-2026-03-31-spedn-consumer-app-shutdown","sources":[{"label":"Flexa SPEDN shutdown","url":"https://x.com/FlexaHQ/status/2039055571790557413","publisher":"x.com","date":"2026-03-31","basis":"primary"},{"label":"Flexa leadership change","url":"https://x.com/FlexaHQ/status/2067612295287484716","publisher":"x.com","date":"2026-03-31","basis":"primary"},{"label":"Flexa SEPA expansion","url":"https://x.com/FlexaHQ/status/2074880812018016287","publisher":"x.com","date":"2026-03-31","basis":"primary"}],"reviewed_at":"2026-08-25"},{"id":"coincards-2025-08-04-security-incident-august-04-2025","service_slug":"coincards","title":"Security Incident - August 04, 2025","type":"breach","severity":"high","status":"ongoing","corroboration":"reported","date":"2025-08-04","discovered_date":"2025-08-04","summary":"Retain incident in canonical data and require a quantified final remediation/affected-user update before treating it as fully resolved.","user_impact":"Retain incident in canonical data and require a quantified final remediation/affected-user update before treating it as fully resolved.","status_note":"The reviewed record does not establish full resolution; remediation is unknown. Independent corroboration was not established in the reviewed source set.","article_url":null,"service_url":"https://cunicula.com/en/provider/coincards","incident_url":"https://cunicula.com/en/incidents#coincards-2025-08-04-security-incident-august-04-2025","sources":[{"label":"Security Incident - August 04, 2025","url":"https://coincards.com/security-incident-august-04-2025/","publisher":"coincards.com","date":"2025-08-04","basis":"primary"}],"reviewed_at":"2026-08-27"},{"id":"trezor-newsletter-email-2024","service_slug":"trezor","title":"Unauthorized newsletter email","type":"breach","severity":"high","status":"resolved","corroboration":"reported","date":"2024-01-24","discovered_date":"2024-01-24","summary":"An unauthorized actor used a separate third-party email service to send Trezor newsletter subscribers an unauthorized newsletter email asking for recovery seeds. Trezor said the event affected newsletter email addresses only, deactivated the link, and restricted unauthorized access. No device, recovery seed, wallet, or funds compromise was reported.","user_impact":"Recipients received a phishing email from Trezor's domain that directed them to a fake page asking for their recovery seed. No device, recovery seed, wallet, or funds compromise was reported.","status_note":"Trezor said it deactivated the malicious link and restricted unauthorized access on 24 January 2024. Corroboration remains reported because the reviewed record has one primary source.","article_url":null,"service_url":"https://cunicula.com/en/provider/trezor","incident_url":"https://cunicula.com/en/incidents#trezor-newsletter-email-2024","sources":[{"label":"Trezor newsletter security alert","url":"https://blog.trezor.io/trezor-security-alert-stay-vigilant-against-an-unauthorized-email-and-continued-phishing-attacks-1b4982c2f53c","publisher":"blog.trezor.io","date":"2024-01-24","basis":"primary"}],"reviewed_at":"2026-08-23"},{"id":"trezor-support-portal-exposure-2024","service_slug":"trezor","title":"Third-party support portal contact exposure","type":"breach","severity":"high","status":"resolved","corroboration":"reported","date":"2024-01-17","discovered_date":"2024-01-17","summary":"Unauthorized access to Trezor's third-party support-ticket portal may have exposed the name/nickname and email address of up to 66,000 support contacts. Phishing followed: the actor emailed 41 users asking for recovery-seed information. No device, recovery seed, wallet, or funds compromise was reported.","user_impact":"Affected contacts faced targeted phishing using support data. No device, recovery seed, wallet, or funds compromise was reported.","status_note":"Trezor said it revoked the unauthorized access on 17 January 2024. Corroboration remains reported because the two reviewed sources are both first-party Trezor notices.","article_url":null,"service_url":"https://cunicula.com/en/provider/trezor","incident_url":"https://cunicula.com/en/incidents#trezor-support-portal-exposure-2024","sources":[{"label":"Trezor support portal security update","url":"https://blog.trezor.io/trezor-security-update-stay-vigilant-against-potential-phishing-attack-bb05015a21f8","publisher":"blog.trezor.io","date":"2024-01-17","basis":"primary"},{"label":"Trezor newsletter security alert","url":"https://blog.trezor.io/trezor-security-alert-stay-vigilant-against-an-unauthorized-email-and-continued-phishing-attacks-1b4982c2f53c","publisher":"blog.trezor.io","date":"2024-01-17","basis":"primary"}],"reviewed_at":"2026-08-23"},{"id":"ledger-2023-12-14-ledger-connect-kit-supply-chain-compromise","service_slug":"ledger","title":"Ledger Connect Kit supply-chain compromise","type":"breach","severity":"critical","status":"resolved","corroboration":"reported","date":"2023-12-14","discovered_date":"2023-12-14","summary":"A phished former employee's NPMJS access was used to publish malicious Ledger Connect Kit versions 1.1.5-1.1.7. DApps dynamically loaded the package and users who approved malicious EVM transactions suffered asset drains. Ledger's report says the attacker did not access Ledger infrastructure, code repositories or the DApps; this was not a compromise of hardware-wallet private-key or recovery-phrase storage. Ledger estimated active draining lasted less than two hours and complete resolution took about five hours.","user_impact":"A phished former employee's NPMJS access was used to publish malicious Ledger Connect Kit versions 1.1.5-1.1.7. DApps dynamically loaded the package and users who approved malicious EVM transactions suffered asset drains. Ledger's report says the attacker did not access Ledger infrastructure, code repositories or the DApps; this was not a compromise of hardware-wallet private-key or recovery-phrase storage. Ledger estimated active draining lasted less than two hours and complete resolution took about five hours.","status_note":"Current review records this incident as resolved; remediation is complete. Corroboration remains reported because fewer than two independent publishers were reviewed.","article_url":null,"service_url":"https://cunicula.com/en/provider/ledger","incident_url":"https://cunicula.com/en/incidents#ledger-2023-12-14-ledger-connect-kit-supply-chain-compromise","sources":[{"label":"Ledger Security Incident Report (2023-12-20)","url":"https://www.ledger.com/blog/security-incident-report","publisher":"www.ledger.com","date":"2023-12-20","basis":"primary"}],"reviewed_at":"2026-08-26"},{"id":"ledger-2020-06-25-e-commerce-and-marketing-database-breach","service_slug":"ledger","title":"E-commerce and marketing database breach","type":"breach","severity":"high","status":"resolved","corroboration":"reported","date":"2020-06-25","discovered_date":"2020-06-25","summary":"Initial 2020-07-29 disclosure: approximately 1 million email addresses and, within that population, a subset of approximately 9,500 customers with detailed contact/order data were exposed. Separately, Ledger's 2020-12-21 update said the public dump showed approximately 272,000 detailed records. The initial disclosure excluded payment information/passwords and Ledger stated there was no hardware-wallet, Ledger Live or crypto-asset impact; leaked contact data created continuing phishing and physical-targeting risk.","user_impact":"Initial 2020-07-29 disclosure: approximately 1 million email addresses and, within that population, a subset of approximately 9,500 customers with detailed contact/order data were exposed. Separately, Ledger's 2020-12-21 update said the public dump showed approximately 272,000 detailed records. The initial disclosure excluded payment information/passwords and Ledger stated there was no hardware-wallet, Ledger Live or crypto-asset impact; leaked contact data created continuing phishing and physical-targeting risk.","status_note":"Current review records this incident as resolved; remediation is complete. Corroboration remains reported because fewer than two independent publishers were reviewed.","article_url":null,"service_url":"https://cunicula.com/en/provider/ledger","incident_url":"https://cunicula.com/en/incidents#ledger-2020-06-25-e-commerce-and-marketing-database-breach","sources":[{"label":"Ledger initial disclosure (2020-07-29)","url":"https://www.ledger.com/addressing-the-july-2020-e-commerce-and-marketing-data-breach","publisher":"www.ledger.com","date":"2020-07-29","basis":"primary"},{"label":"Ledger later public-dump update (2020-12-21)","url":"https://www.ledger.com/message-ledgers-ceo-data-leak","publisher":"www.ledger.com","date":"2020-12-21","basis":"primary"}],"reviewed_at":"2026-08-26"}],"meta":{"total":28,"api_version":"1.3","powered_by":"cunicula.com","documentation_url":"https://cunicula.com/en/api-docs","machine_index_url":"https://cunicula.com/llms.txt","license":"LicenseRef-Cunicula-Attribution-1.0","license_url":"https://cunicula.com/en/cite","attribution":"Cunicula, \"{name}\", cunicula.com, reviewed {reviewed}, retrieved {retrieved}, {url}","cite_guide_url":"https://cunicula.com/en/cite","dataset_url":"https://cunicula.com/api/v1/dataset","schema_version":"1.1.0","filters":{},"counts":{"records":28,"confirmed":1,"reported":27,"ongoing":11,"services_affected":18},"definitions":{"type":{"breach":"Unauthorised access to systems or user data, confirmed by the operator or by a party who examined the evidence.","vulnerability":"A defect in a shipped product that exposes users to loss, whether or not it was exploited.","exit-scam":"An operator stopped honouring withdrawals or redemptions while continuing to hold user funds, with no credible wind-down.","seizure":"A state actor took control of infrastructure, funds, or domains.","policy-change":"A change in terms, KYC posture, or jurisdiction that materially alters what a user is exposed to.","shutdown":"The operator ended a product or the whole service, whether or not obligations were settled.","legal":"Charges, sanctions, injunctions, or a judgment against the operator.","outage":"A service or public surface became unavailable while the operator or underlying network continued."},"status":{"ongoing":"The exposure is still live for at least some users as of the review date on the record.","resolved":"The operator or an outside party closed the exposure and obligations were settled.","disputed":"The parties disagree on the facts and no record read for this row settles it.","unpatched":"A fix exists in principle but has not shipped, or shipped without repairing users already affected."},"corroboration":{"confirmed":"Three or more sources were read directly, at least one of them primary: the operator's own advisory, a court or government record, or the vendor's own repository. This is the bar an article must clear.","reported":"Fewer than three sources, or no primary source. The row is recorded because it bears on user risk, but it rests on what one party published and Cunicula has not independently confirmed it."}},"scope":"Dated security and solvency incidents affecting services in the Cunicula directory. Rows marked corroboration=reported rest on a single account and have not been independently confirmed; they are recorded because they bear on user risk, not because they are established. This endpoint covers incidents an editor reviewed and is not a census of everything that has happened to these services."}}