Web3 Daily Exploits — 10 Sep 2026: Quiet Window — Trezor Vendor-Email Phish
No new confirmed protocol drain in the last 24 hours. The window’s first-report item is a Trezor third-party email-provider breach that sent a fake STM32 entropy alert from legitimate sending infrastructure. A Defimon 10,000 USDC recovery ping remains unverified as a protocol exploit.

This is a quiet protocol-exploit window after yesterday’s two Ethereum drains. Required monitors were checked through the 10 Sep 2026 America/Panama cutoff: DefimonAlerts, CertiKAlert, Phalcon, GoPlusSecurity, SlowMist_Team, PeckShieldAlert, BlockSecTeam, Lookonchain, ZachXBT, CyversAlerts, Immunefi, and rekt.news. No desk published a first-report smart-contract drain with a new on-chain loss figure in this 24-hour slice. The item that did move was off-chain: Trezor confirmed that a third-party email provider had been breached and that a “Critical Security Alert: STM32 Entropy Vulnerability” mail was phishing. CertiKAlert, PeckShieldAlert, and GoPlusSecurity all relayed that official warning. Live protocol loss scored on this card is $0.
Yesterday’s order-factory (~24.7 ETH) and deprecated Enso DPI vault (~5.6 ETH) items stay on the 9 Sep brief. They are not re-scored. The Liquid Federation remainder of ~598.5 BTC is unchanged. Defimon posted two recovery threads — a follow-up on the older MiniRouter2 / Robinhood Chain case, and a new on-chain message alleging an unauthorized 10,000 USDC move from a truncated address — neither of which is treated here as a confirmed first-report protocol exploit. All dollar figures below are amounts still outside the affected party’s control only when a transaction is cited.
Trezor / shared newsletter stack — vendor-email breach + STM32 phishing (off-chain) — Confirmed
What happened: At 20:37 UTC on 9 Sep 2026, Trezor posted that its third-party e-mail provider had been breached. Recipients of a message titled “Critical Security Alert: STM32 Entropy Vulnerability” were told the mail was not from Trezor and that no link in it should be opened. Trezor said it had taken down “the domain” and was investigating how attackers obtained use of its legitimate sending domain. The same window produced matching warnings from BitBox and coverage that CoinTracking was in the same blast. GoPlus noted the vendor-email blast was also hitting CoinTracking and BitBox users.
Protocol / chain / asset: Off-chain vendor compromise against hardware-wallet and portfolio-tracker mailing lists. No Trezor device firmware bug was demonstrated. No confirmed on-chain protocol drain is attached to this incident in the cutoff. Assets at risk are whatever a recipient would type, sign, or install after following the phishing link — seed phrases, xPubs, or a fake “device check.”
Loss: No confirmed protocol or hardware-wallet treasury loss in this window. Do not invent a dollar figure. Individual victim wallets, if any, have not been tabulated by the monitors listed above.
Attack type: Third-party email-provider compromise used to send phishing that inherited the victim brand’s legitimate From address / domain. Separate reporting in the window (Blocktrainer via secondary write-ups; Incrypted citing a Trezor comment) names Brevo, formerly Sendinblue, as the shared newsletter platform and describes unauthorized API keys created inside affected accounts. Trezor’s own first post did not name the vendor. Treat the Brevo identification as reported, not as a courtroom finding that Brevo’s core platform was globally owned.
Technical details: The lure is a fake STM32 microcontroller “entropy” / RNG advisory. That framing is designed to make a careful hardware-wallet owner open a “device check” rather than ignore a generic giveaway. Trezor later reiterated on-thread that it will not call users by phone, does not run phone support, and will never ask for a wallet backup off the device. GoPlus’s 10 Sep 02:52 UTC alert is the cleanest operational summary from the required monitor set: if an email from help@trezor.io with that subject tells the reader to click a link and run a device check, stop. CertiKAlert (01:24 UTC 10 Sep) and PeckShieldAlert (01:41 UTC 10 Sep) quoted the official Trezor post and added no new loss figure.
Secondary reporting in the same window is consistent on three points and thin on a fourth. Consistent: (1) the subject line; (2) Trezor’s statement that the provider and the sending domain were abused; (3) BitBox and CoinTracking appearing in the same blast. Thin: a public, vendor-issued root-cause report that distinguishes account-level API-key theft from a compromise of Brevo itself. Incrypted’s 10 Sep note that a Trezor representative named Brevo in a comment is recorded here as that outlet’s attribution. This brief does not convert that comment into a confirmed platform-wide Brevo incident.
Explorer links: None. This is not an on-chain contract drain. Official channel: https://x.com/Trezor/status/2097786518110609620.
Status: Confirmed as a vendor-email / phishing incident by Trezor. Relayed by CertiKAlert, PeckShieldAlert, and GoPlusSecurity. Investigation open. No confirmed seed-extraction or protocol-loss total at cutoff.
Sources: https://x.com/Trezor/status/2097786518110609620, https://x.com/CertiKAlert/status/2097858602497417262, https://x.com/PeckShieldAlert/status/2097863078406930739, https://x.com/GoPlusSecurity/status/2097880966232703385
Unauthorized 10,000 USDC move — Ethereum — Unverified / recovery ping
What happened: At 21:23 UTC on 9 Sep 2026, DefimonAlerts published an on-chain message: “On Sep 9 you moved 10,000 USDC out of 0x32F6…6641 without authorization. Offer: return 8,000 USDC to this sender address and keep 2,000 as a bounty for the return.” The URL attached to that post is an Ethereum transaction that is itself the message, not the alleged USDC transfer.
Protocol / chain / asset: Ethereum / USDC. No protocol name, pool, or router was given. The victim is truncated to 0x32F6...6641.
Loss: Claimed 10,000 USDC. Not independently reconstructed from a transfer hash in the Defimon post. The cited transaction 0x9c9be201e710f2eb9bd0cc23926b9e42e245963834cf77e03b781ec4f1709310 is dated 9 Sep 2026 21:22:59 UTC, sends 0.00001 ETH from 0x9445c7af150d3C972E0AbD4D254C56674f1952bd to 0xe2907F66affdAC913EC20df8526F1213273B1A0e, and carries the recovery text in calldata. Etherscan shows no ERC-20 transfer on that hash. Do not treat 10,000 USDC as a confirmed live protocol loss on this card.
Attack type: Unspecified unauthorized transfer, as alleged by the message sender. Could be key compromise, allowance abuse, address poisoning, or an internal dispute. Insufficient public detail to classify.
Technical details: Recovery-desk pings of this form are common after a victim or desk notices an outflow. They are not a substitute for a SlowMist / Phalcon / PeckShield first-report with a victim contract and an exploit transaction. Until a USDC Transfer event that matches the truncated address and the 10,000 unit size is published by a monitor, this item stays in the unverified column.
Explorer links:
- On-chain message (not the alleged drain): https://etherscan.io/tx/0x9c9be201e710f2eb9bd0cc23926b9e42e245963834cf77e03b781ec4f1709310
Status: Unverified as a protocol exploit. Recorded as a recovery offer only.
Sources: https://x.com/DefimonAlerts/status/2097797969646920187
Also noted
- MiniRouter2 / Robinhood Chain (UPDATE, recovery): Defimon followed up at 23:05 UTC on 9 Sep. SEAL 911 told the desk the destination address is restricted on Robinhood Chain (4663) and cannot move the 12.237 ETH proceeds there. The same 10% bounty (retain 1.2237 ETH, return 11.0135 ETH) was restated, with the reply requested on Ethereum mainnet. Original drain remains the earlier MiniRouter2 transaction
0xacce7431a0019bda373f60f2da37f70b1415d077b6d62851bc17f6bf596b14ce. Not a new first-report exploit. Source: https://x.com/DefimonAlerts/status/2097823842269897018. - Liquid Network (UPDATE, not re-scored): 3,400 BTC returned earlier; ~598.5 BTC still held by the self-described whitehats. No new return transaction in this cutoff. Sources remain the 7–8 Sep CertiK / PeckShield / GoPlus posts already cited on 8 and 9 Sep.
- Order factory ~24.7 ETH and Enso deprecated vault ~5.6 ETH: First-reported on 9 Sep by SlowMist and already scored on yesterday’s brief. No material new loss figure after that cutoff.
- Balancer V1 (6 Sep) and Stake DAO vsdCRV (May 2026): Recovery / legal-deadline threads from 8 Sep. Deadlines still 15 Sep. Not new drains.
- OFAC / DOJ vs Xinbi Guarantee: SlowMist at 11:07 UTC on 10 Sep summarized a 9 Sep OFAC/DOJ action restricting more than $52M and seizing related Telegram channels and wallets. Compliance action, not a smart-contract exploit. Source: https://x.com/SlowMist_Team/status/2098005323244306523.
- $LAPTOP (Base): GoPlus published a 10 Sep token-risk note after a ~99% drawdown from a thin-pool ATH. Contract scan reported no backdoor; the piece is liquidity / concentration / market-maker flow, not a protocol drain. Earlier 9 Sep GoPlus warning on $LAPTOP airdrop phishing sites and same-ticker clones still applies. Sources: https://x.com/GoPlusSecurity/status/2097945311490756880, https://x.com/GoPlusSecurity/status/2097632697216831784.
- Lookonchain: whale $HYPE accumulation, a $ZEC short, and $LAPTOP dip-buying. No exploit first-report.
- ZachXBT: 9 Sep posts on centralized-platform breach handling and an older 2024 social-engineering case (Malone guilty plea). No fresh on-chain protocol drain.
- Phalcon / BlockSec: 10 Sep product post on blockchain penetration testing. No incident alert.
- Immunefi: leaderboard / Studio Review / ENS competition stats. No incident.
- CyversAlerts and rekt.news: no qualifying first-report protocol exploit in this cutoff.
Sources & references
- https://x.com/Trezor/status/2097786518110609620
- https://x.com/CertiKAlert/status/2097858602497417262
- https://x.com/PeckShieldAlert/status/2097863078406930739
- https://x.com/GoPlusSecurity/status/2097880966232703385
- https://x.com/DefimonAlerts/status/2097797969646920187
- https://etherscan.io/tx/0x9c9be201e710f2eb9bd0cc23926b9e42e245963834cf77e03b781ec4f1709310
- https://x.com/DefimonAlerts/status/2097823842269897018
- https://x.com/SlowMist_Team/status/2098005323244306523
- https://x.com/GoPlusSecurity/status/2097945311490756880
- https://x.com/CertiKAlert/status/2097287047014752449
Editor’s note: Card live-loss is this window’s confirmed new protocol drains only ($0). Trezor is scored as one off-chain incident. The 10,000 USDC Defimon ping is flagged unverified because the linked hash is the recovery message, not a USDC Transfer. Liquid’s unpaid 598.5 BTC is carried as an update. Whitehat and bounty claims are recorded as claims. No how-to or exploit reproduction steps. Verify explorers and official channels before acting on any alert.
Read more

Web3 Daily Exploits — 12 Sep 2026: Zentra ~$140k Citrea Drain + ORB Reentrancy
First public desk confirmation of Zentra’s 9 Sep ctUSD reserve drain on Citrea (~$140k official / ~$143k Defimon), a SlowMist-confirmed ~$32.6k ORB reentrancy on BNB Chain, and a pending fake rollup assertion against Edgeless’s dormant L1 bridge (~9.2 ewETH at risk).

Web3 Daily Exploits — 11 Sep 2026: Symbiosis ~$336k WBTC Dump + Three Small Drains
Four first-report protocol items in the last 24 hours: Symbiosis BridgeV2 minted unbacked syBTC on BNB Chain and realized ~$336k in WBTC on Ethereum; BeatXswap lost ~$64k–$78k to a spot-oracle flash loan; ether.fi’s legacy AtomicQueue lost ~15.45 ETH; OMNI404 lost 2.4 WETH.

Web3 Daily Exploits — 9 Sep 2026: Order Factory ~24.7 ETH + Enso Deprecated Vault ~5.6 ETH
Two confirmed Ethereum drains in the last 24 hours: an unnamed order-factory access-control miss took ~24.7 ETH, and leftover funds in a deprecated Enso DPI strategy vault were pulled for ~5.6 ETH. No new eight-figure protocol loss in this window.

Web3 Daily Exploits — 08 Sep 2026: Liquid $47M Still Out + BNB Router Drains
Liquid actors returned 3,400 BTC and kept ~598.5 BTC (~$47M) without a signed bounty. Two fresh BNB Chain drains: a DEX router approval sweep of ~62.28 BNB and a WealthManagementV2 owner-key hit for 26,414 USDT.

