So, the recent NPM attack on several Bitcoin wallets (by address poisoning) is well-known by now. I have not done any on-chain transfer since then, and trying to stay updated about the developments.
I am using the Trezor one for cold storage, and Blockstream Green for some spending and transfer. So far, I have seen tweets on X from both Trezor and Blockstream claiming their toolchains are totally unaffected so far.
But, keeping up with the ethos of Bitcoin, instead of trusting, is it possible to verify? In particular, four distinct components here for which I wish for some kind of reasonably ironclad guarantees
- Trezor One hardware
- Trezor Suite
- Blockstream Green Android version
- Blockstream Desktop (AppImage version)
How to verify that they are not affected, if possible?
Footnotes
Footnotes