- Blockstream refused a ransom demand for roughly 598 to 600 BTC still missing from the Liquid Network exploit and said it will cover the shortfall itself.
- A login compromise at Trezor’s third-party email vendor, Brevo, let attackers send phishing emails to about 347,000 newsletter subscribers.
- Trezor said its own infrastructure, hardware devices, and user wallets were not touched by the Brevo breach.
Two incidents this week underscored a divide in crypto security: one about how a company responds after an exploit, the other about how a breach at a third-party vendor can put users at risk without the crypto company’s own systems ever being touched.
Blockstream said it will not pay a ransom demand tied to the roughly 598 to 600 BTC still unaccounted for following an exploit of its Liquid Network sidechain, out of an original theft estimated near $320 million. The attacker reportedly sought a payment equal to roughly 10 percent of the remaining funds in exchange for returning the rest, a structure sometimes used in crypto exploits as an informal negotiation, where the attacker frames the theft as an unsolicited security assessment deserving compensation rather than a crime. Blockstream rejected that framing directly, describing the funds as stolen property rather than something to be negotiated over, and said it would cover the shortfall from its own resources rather than reward whoever carried out the exploit.
That stance carries a deliberate signal beyond this single incident. Paying ransoms or bounties to exploiters, even when framed as a white-hat negotiation, has long been contested in crypto security circles: some protocols have used it to recover the bulk of stolen funds, while critics argue it normalizes exploitation as a viable, low-risk way to extract a payout. Blockstream’s refusal puts it firmly on the side of treating exploits as straightforward theft, a position that carries reputational weight precisely because other protocols have set the opposite precedent in past incidents. Blockstream’s own site is the company’s primary official channel for updates on the Liquid Network incident.
The Trezor situation is a different category of risk entirely. Trezor disclosed that Brevo, a third-party email service provider it uses to send newsletters, suffered a login compromise that let attackers access subscriber data and use it to send phishing emails to roughly 347,000 of Trezor’s own newsletter subscribers. Trezor’s own incident disclosure names other companies that use Brevo, including BitBox and CoinTracking, as also affected by the same underlying breach, indicating the compromise sat with the vendor rather than with any individual crypto company’s own systems. Trezor was explicit that the breach did not reach its infrastructure, hardware devices, or user wallets directly; the risk to subscribers comes entirely from the phishing emails themselves, which could attempt to trick recipients into revealing seed phrases or approving malicious transactions.
The incident is a reminder of how much of the crypto industry’s security surface now sits outside companies’ own infrastructure, in the vendors they rely on for functions like email delivery, customer support, or analytics. A hardware wallet maker can run a genuinely secure device and still expose its customer base to targeted phishing through a vendor breach it does not control and cannot directly patch. For anyone who receives newsletter email from a hardware wallet provider, the practical lesson is the same one that applies after most phishing-adjacent breaches: treat unexpected security alerts or login prompts arriving by email with more suspicion than usual, and verify any urgent request through the company’s app or official site rather than a link in the email itself.
Disclaimer: Cryip's content is strictly for educational and informational purposes and does not constitute financial, legal, or investment advice. Cryptocurrency involves significant risk, and readers assume full responsibility for their own financial decisions. Asset references are never endorsements.
To make complex crypto topics accessible to readers at all experience levels, our team uses AI tools strictly to refine language, correct grammar, and simplify terminology. AI is never used to draft facts, source information, or form conclusions. Every article is fact-checked and approved by a human editor before publication. Read our full AI Use & Content Policy.












