Blockstream Refuses Ransom Demand, Trezor Hit by Vendor Breach
Blockstream has refused a ransom demand of around $77,250 in Bitcoin for roughly 598 to 600 BTC still missing from the Liquid Network exploit. The company will cover the shortfall itself.
The incident highlights Blockstream's stance on paying ransoms or bounties to exploiters, which it views as treating exploits as straightforward theft. This position is seen as a deliberate signal that carries reputational weight in the crypto security circles.
Trezor, another major player in the industry, was affected by a login compromise at its third-party email vendor, Brevo. Attackers used this breach to send phishing emails to around 347,000 of Trezor's newsletter subscribers. However, Trezor emphasized that its own infrastructure, hardware devices, and user wallets were not touched by the breach.
The incident serves as a reminder of how much of the crypto industry's security surface now sits outside companies' own infrastructure, in the vendors they rely on for functions like email delivery or customer support. This raises concerns about the risks associated with third-party vendor breaches.