News

Global security awareness — not only PulseChain.

Permalink for this incident. Same content as the News feed — use Share to post it.

Cross-chain security awareness in plain English. Not an audit. Not financial advice. We never publish drain recipes or exploit steps. News items are research snapshots from public reporting — not always a full 369 deep-dive.

highCustody / hardwarephishing

Trezor: ShipMonk shipping-provider breach exposes order PII

13 Aug 2026: Trezor disclosed that ShipMonk, a fulfillment partner, had unauthorized access to customer order data. About 11,742 buyers had full exposure (name, email, phone, shipping address) and 1,947 partial (name, city, email) — limited to recent orders in US, UK, Sweden, Colombia, Brazil, Italy, and Portugal within the 90 days before 8 Aug 2026. Trezor states its own systems, devices, private keys, and wallet backups were not compromised. Affected customers were emailed from @trezor.io; the real risk called out is more sophisticated phishing by mail, phone, or email. Confirmed via official Trezor blog + @Trezor post.

369 take: A hardware wallet can be fine and you can still get hunted — name, address, and phone from a shipper are enough for fake “support / firmware / delivery” plays. Never enter a seed or backup on a website or over the phone; only trust updates on official Trezor channels. Pulse lesson: treat any vendor or logistics PII leak as a phishing season for that cohort, not as proof the device itself was drained.