Today's lead: Swiss Bitcoin Pay took its entire infrastructure offline after detecting a suspected intrusion — our full coverage is here. The rest of the day's security news, in brief:

Solana Mobile: Second Crypto Name Confirmed in the Brevo Breach

Solana Mobile told users on September 12 that its marketing email account at Brevo — the email platform behind last week's Trezor newsletter phishing wave — was accessed without authorization as part of the wider Brevo security incident.

The company said it identified the unauthorized access, disabled the account outright, and is working with Brevo to determine what information the attacker may have reached. Solana Mobile says it has no evidence that unauthorized emails were sent from its account, though it is still verifying that with Brevo. The disclosure makes it the second prominent crypto company confirmed among the 138 Brevo customer accounts reached through the SAML SSO flaw, after Trezor's roughly 347,000 exposed newsletter subscribers.

The practical guidance is unchanged but worth repeating: no legitimate project emails asking for a seed phrase, private key, or wallet recovery information. Ever.

Liquid Network: Week Two Begins, Peg-Outs Still Locked

The Liquid Network enters its second week since roughly 4,000 BTC (~$320 million) left the federation's reserves with Bitcoin peg-outs still disabled. Internal transactions are processing and blocks are flowing, but LBTC holders still cannot withdraw to the mainchain.

The arithmetic hasn't changed: about 3,400 BTC was returned by the self-described white hats, leaving roughly 598 BTC outstanding, with the network reported to be around 85% collateralized. Blockstream has publicly refused the attackers' bounty demand and is working with law enforcement and forensic partners. The post-mortem traced the incident to a proof-verification cache bug patched in Elements 23.3.4. Watch for the collateralization decision — it determines when, and at what parity, peg-outs can safely reopen.

Symbiosis: From Bounty to Informant Reward

With the white-hat window expired and no return of funds announced, Symbiosis has redirected the 20% reward it offered its attacker to anyone whose information leads to recovery. Approximately 15 BTC sits recovered in a team-controlled multisig; BTC routes on the cross-chain protocol remain halted while the exploit investigation continues.

Revolut: Extortion Escalates, Investigation Continues

The actors behind the fraudulent government data request are reportedly demanding 10,000 BTC and threatening daily data dumps. Revolut has not confirmed the demand or authenticated the leaked files; the police investigation continues. Our full analysis of the escalation is here.

TrustGrade tracks the security posture of wallet vendors, protocols, and exchanges. Security scans with verified, registry-backed scores arrive with TrustGrade Code Scoring in December 2026.