<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/">
  <channel>
    <title>Security — EasyCryptoGuides</title>
    <link>https://easycryptoguides.com/</link>
    <description>Latest Security coverage on EasyCryptoGuides.</description>
    <language>en-gb</language>
    <atom:link href="https://easycryptoguides.com/news/security/rss.xml" rel="self" type="application/rss+xml"/>
    <item>
      <title>Trezor’s shipping partner leaked customer details. The device is not the leak.</title>
      <link>https://easycryptoguides.com/news/trezor-shipmonk-leak-a-parcel-vendor-is-not-the-wallet</link>
      <guid isPermaLink="true">https://easycryptoguides.com/news/trezor-shipmonk-leak-a-parcel-vendor-is-not-the-wallet</guid>
      <pubDate>Thu, 13 Aug 2026 15:00:00 GMT</pubDate>
      <dc:creator>EasyCryptoGuides</dc:creator>
      <description>ShipMonk told Trezor it had unauthorised access to order data. About 13,700 recent buyers were exposed. Hardware wallets and keys were not.</description>
    </item>
    <item>
      <title>Coinbase’s contractor breach is an insider story, not a chain failure</title>
      <link>https://easycryptoguides.com/news/coinbase-contractor-breach-insiders-are-still-a-custody-risk</link>
      <guid isPermaLink="true">https://easycryptoguides.com/news/coinbase-contractor-breach-insiders-are-still-a-custody-risk</guid>
      <pubDate>Wed, 14 May 2025 21:00:00 GMT</pubDate>
      <dc:creator>EasyCryptoGuides</dc:creator>
      <description>In a 14 May 2025 filing, Coinbase said overseas support contractors stole account data and that it would not pay a $20 million ransom. Keys in cold storage were not the headline. Names were.</description>
    </item>
    <item>
      <title>The Bybit theft was a company wallet. The chain did what signatures do.</title>
      <link>https://easycryptoguides.com/news/bybit-hack-largest-exchange-theft-still-a-company-wallet</link>
      <guid isPermaLink="true">https://easycryptoguides.com/news/bybit-hack-largest-exchange-theft-still-a-company-wallet</guid>
      <pubDate>Fri, 21 Feb 2025 18:00:00 GMT</pubDate>
      <dc:creator>EasyCryptoGuides</dc:creator>
      <description>Bybit lost a record sum from a wallet its signers controlled. Later attribution pointed at North Korea. A 2026 lawsuit tries to freeze what can still be reached.</description>
    </item>
    <item>
      <title>DMM Bitcoin’s theft is Japan’s custody lesson, again</title>
      <link>https://easycryptoguides.com/news/dmm-bitcoin-hack-japan-exchange-theft-after-coincheck</link>
      <guid isPermaLink="true">https://easycryptoguides.com/news/dmm-bitcoin-hack-japan-exchange-theft-after-coincheck</guid>
      <pubDate>Fri, 31 May 2024 06:00:00 GMT</pubDate>
      <dc:creator>EasyCryptoGuides</dc:creator>
      <description>On 31 May 2024 DMM Bitcoin reported an unauthorised outflow of 4,502.9 BTC. A company wallet was emptied. Bitcoin’s rules were not.</description>
    </item>
    <item>
      <title>Trezor’s support portal leak was a helpdesk, not the device</title>
      <link>https://easycryptoguides.com/news/trezor-support-portal-leak-was-a-helpdesk-not-the-device</link>
      <guid isPermaLink="true">https://easycryptoguides.com/news/trezor-support-portal-leak-was-a-helpdesk-not-the-device</guid>
      <pubDate>Wed, 17 Jan 2024 20:00:00 GMT</pubDate>
      <dc:creator>EasyCryptoGuides</dc:creator>
      <description>On 17 January 2024 Trezor said a support ticketing vendor had been accessed. Hardware wallets stayed intact. The inbox did not.</description>
    </item>
    <item>
      <title>A hacked SEC account is not an ETF approval</title>
      <link>https://easycryptoguides.com/news/sec-x-hack-a-compromised-account-is-not-an-approval</link>
      <guid isPermaLink="true">https://easycryptoguides.com/news/sec-x-hack-a-compromised-account-is-not-an-approval</guid>
      <pubDate>Tue, 09 Jan 2024 21:00:00 GMT</pubDate>
      <dc:creator>EasyCryptoGuides</dc:creator>
      <description>Someone took the phone number behind the SEC’s X login and announced ETF approval a day early. Social media is not the Federal Register.</description>
    </item>
    <item>
      <title>The Ronin hack was a bridge with too few keys, not Ethereum failing</title>
      <link>https://easycryptoguides.com/news/ronin-bridge-hack-was-a-bridge-not-the-chain-failing</link>
      <guid isPermaLink="true">https://easycryptoguides.com/news/ronin-bridge-hack-was-a-bridge-not-the-chain-failing</guid>
      <pubDate>Wed, 23 Mar 2022 18:00:00 GMT</pubDate>
      <dc:creator>EasyCryptoGuides</dc:creator>
      <description>Sky Mavis’s sidechain bridge did what a 5-of-9 scheme does when five keys are in the wrong hands. Ethereum mainnet kept producing blocks. The game’s on-ramp did not.</description>
    </item>
    <item>
      <title>Wormhole was a bridge bug. Jump put the ETH back.</title>
      <link>https://easycryptoguides.com/news/wormhole-hack-was-a-bridge-bug-jump-made-users-whole</link>
      <guid isPermaLink="true">https://easycryptoguides.com/news/wormhole-hack-was-a-bridge-bug-jump-made-users-whole</guid>
      <pubDate>Wed, 02 Feb 2022 18:00:00 GMT</pubDate>
      <dc:creator>EasyCryptoGuides</dc:creator>
      <description>A signature-check failure on the Solana side of a cross-chain bridge printed IOUs that were not matched by ether on Ethereum. Users of the wrapped token got made whole by a company, not by maths.</description>
    </item>
    <item>
      <title>Poly Network’s $610m hole was a bridge bug. The chains kept running.</title>
      <link>https://easycryptoguides.com/news/poly-network-hack-a-bridge-bug-is-not-the-chains-failing</link>
      <guid isPermaLink="true">https://easycryptoguides.com/news/poly-network-hack-a-bridge-bug-is-not-the-chains-failing</guid>
      <pubDate>Tue, 10 Aug 2021 16:00:00 GMT</pubDate>
      <dc:creator>EasyCryptoGuides</dc:creator>
      <description>A little-known interoperability protocol lost on the order of $610 million, then spent two weeks getting it returned. Ethereum did not halt. A keeper path did.</description>
    </item>
    <item>
      <title>Ledger’s shop dump was a mailing list, not the device</title>
      <link>https://easycryptoguides.com/news/ledger-data-leak-a-shop-database-is-not-the-device</link>
      <guid isPermaLink="true">https://easycryptoguides.com/news/ledger-data-leak-a-shop-database-is-not-the-device</guid>
      <pubDate>Sun, 20 Dec 2020 18:00:00 GMT</pubDate>
      <dc:creator>EasyCryptoGuides</dc:creator>
      <description>A million emails, plus a large slice of postal details. Hardware wallets stayed intact. Phishing and, later, worse mail, used the list. Cold storage does not encrypt the invoice.</description>
    </item>
    <item>
      <title>KuCoin’s theft was hot-wallet keys, not a broken chain</title>
      <link>https://easycryptoguides.com/news/kucoin-hack-was-hot-wallet-keys-not-a-broken-chain</link>
      <guid isPermaLink="true">https://easycryptoguides.com/news/kucoin-hack-was-hot-wallet-keys-not-a-broken-chain</guid>
      <pubDate>Fri, 25 Sep 2020 19:00:00 GMT</pubDate>
      <dc:creator>EasyCryptoGuides</dc:creator>
      <description>Initial headlines said $150 million; later tallies sat near $275–285 million across BTC, ETH and a pile of ERC-20s. An exchange login is still a company wallet.</description>
    </item>
    <item>
      <title>Binance’s 7,000 BTC theft is why SAFU existed</title>
      <link>https://easycryptoguides.com/news/binance-hot-wallet-theft-and-what-safu-was-for</link>
      <guid isPermaLink="true">https://easycryptoguides.com/news/binance-hot-wallet-theft-and-what-safu-was-for</guid>
      <pubDate>Tue, 07 May 2019 20:00:00 GMT</pubDate>
      <dc:creator>EasyCryptoGuides</dc:creator>
      <description>Phishing and malware against users, then one withdrawal that passed existing checks. Roughly $41 million at the day’s print. Bitcoin confirmed a signature. It did not fail.</description>
    </item>
    <item>
      <title>Coincheck’s NEM theft was an exchange wallet, not a broken ledger</title>
      <link>https://easycryptoguides.com/news/coincheck-hack-was-an-exchange-theft-not-a-broken-chain</link>
      <guid isPermaLink="true">https://easycryptoguides.com/news/coincheck-hack-was-an-exchange-theft-not-a-broken-chain</guid>
      <pubDate>Fri, 26 Jan 2018 14:00:00 GMT</pubDate>
      <dc:creator>EasyCryptoGuides</dc:creator>
      <description>Then the largest exchange theft by dollar print. A Tokyo shop that was still only “deemed” registered kept customer NEM online. Custody vs the chain is the whole story.</description>
    </item>
  </channel>
</rss>