Skip to content
CUNICULA

Incident Tracker

Dated security and solvency incidents affecting services in this directory, and how far the sourcing goes on each one.

28Incidents
1Confirmed
27Reported only
11Still open
Every incident was read against its own sources on . This page lists incidents an editor reviewed and is not a census of everything that has happened to these services. An incident is recorded here only after review; automated detection files leads for an editor and never publishes.

How to read a record

CONFIRMED
Three or more sources were read directly, at least one of them primary: the operator's own advisory, a court or government record, or the vendor's own repository. This is the bar an article must clear.
REPORTED
Fewer than three sources, or no primary source. The row is recorded because it bears on user risk, but it rests on what one party published and Cunicula has not independently confirmed it.

Status words

The exposure is still live for at least some users as of the review date on the record.
The operator or an outside party closed the exposure and obligations were settled.
The parties disagree on the facts and no record read for this row settles it.
A fix exists in principle but has not shipped, or shipped without repairing users already affected.
Sort byDateSeverityService

Brevo newsletter export and fraudulent STM32 email

Trezor · BREACH

REPORTED
Incident date
Recorded
Reviewed

Trezor's September 17, 2026 update reports 347,149 newsletter email addresses exported through Brevo. The September 9 message headed 'Critical Security Alert: STM32 Entropy Vulnerability' was phishing: its app requested a wallet backup, not a genuine hardware repair. Trezor says no product, wallet or account system was affected and no passwords or wallet data were held in this list. Brevo says the messages passed email authentication, and attacker access is closed; active here means residual phishing exposure. Do not follow the email links or disclose a backup; delete the message. If a backup was entered, Trezor directs an immediate transfer to a new wallet using its official guide. A firmware update does not undo contact-data exposure. Sources checked September 21, 2026.

What this means for a userContinuing targeted phishing from exported emails. No verified loss-of-funds total in the reviewed disclosures. A convincing sender does not authenticate a request for a wallet backup.

Why it carries this statusDate follows Trezor's September 9 incident account; Brevo dates detection to September 10 at 06:30 UTC and closure of the entry route to 08:30 UTC. These are attributed milestones, not a reconciled forensic start time. Brevo says access was closed and sessions reset; Trezor suspended its account and disabled links. Ongoing denotes residual exported-data/phishing exposure, not continuing attacker access or a hardware vulnerability. Brevo's postmortem describes a permanent fix as being deployed, not independently verified here. Corroboration remains reported: the two affected companies' accounts were reviewed, not an independent forensic audit.

Simsup private-network storefront route degradation

Simsup · OUTAGE

REPORTED
Incident date
Recorded
Reviewed

The prior review recorded an unreliable Tor route. The current status page reports the storefront, payments and served private-network routes operational; one recent I2P payment check failed but no ongoing service outage is reported.

What this means for a userThe prior review recorded an unreliable Tor route. The current status page reports the storefront, payments and served private-network routes operational; one recent I2P payment check failed but no ongoing service outage is reported.

Why it carries this statusThe reviewed record marks this incident resolved; remediation is complete. Independent corroboration was not established in the reviewed source set.

Support impersonation and phishing campaign targeting SageSwap users

SageSwap · BREACH

REPORTED
Incident date
Recorded
Reviewed

SageSwap reports an active campaign impersonating its support across Telegram and platform accounts and warns that support will never request wallet connection or wallet information. No resolution notice was found.

What this means for a userSageSwap reports an active campaign impersonating its support across Telegram and platform accounts and warns that support will never request wallet connection or wallet information. No resolution notice was found.

Why it carries this statusThe reviewed record does not establish full resolution; remediation is unresolved. Independent corroboration was not established in the reviewed source set.

PikaSIM network connectivity interruption (03:31 UTC)

PikaSIM · OUTAGE

REPORTED
Incident date
Recorded
Reviewed

The current official status history records a resolved network-connectivity issue at 03:31 UTC on 21 August 2026; no data or asset compromise is claimed.

What this means for a userThe current official status history records a resolved network-connectivity issue at 03:31 UTC on 21 August 2026; no data or asset compromise is claimed.

Why it carries this statusThe reviewed record marks this incident resolved; remediation is complete. Independent corroboration was not established in the reviewed source set.

PikaSIM network connectivity interruption (05:15 UTC)

PikaSIM · OUTAGE

REPORTED
Incident date
Recorded
Reviewed

The current official status history records a second resolved network-connectivity issue at 05:15 UTC on 21 August 2026; no data or asset compromise is claimed.

What this means for a userThe current official status history records a second resolved network-connectivity issue at 05:15 UTC on 21 August 2026; no data or asset compromise is claimed.

Why it carries this statusThe reviewed record marks this incident resolved; remediation is complete. Independent corroboration was not established in the reviewed source set.

Python CI workflow allowed pull-request code execution

RoboSats · VULNERABILITY

REPORTED
Incident date
Recorded
Reviewed

GHSA-rxx8-rv5g-wpch describes a high-severity pull_request_target workflow flaw through 0.8.5-alpha. RoboSats identifies 0.8.6-alpha as patched and that release was already current when the advisory was published.

What this means for a userGHSA-rxx8-rv5g-wpch describes a high-severity pull_request_target workflow flaw through 0.8.5-alpha. RoboSats identifies 0.8.6-alpha as patched and that release was already current when the advisory was published.

Why it carries this statusThe reviewed record marks this incident resolved; remediation is complete. Independent corroboration was not established in the reviewed source set.

Machine-readable at /api/v1/incidents and as RSS at /incidents/feed.xml. Both carry the corroboration field on every record.

Evidence basis: Claims on this page are linked to published sources for comparison, not certification, audit, endorsement, or recommendation; read the methodology and coverage map before relying on an entry.

Incident Tracker | Cunicula