pull down to refresh

Phishing attack underway targeting @BitBoxSwiss and @Trezor customers.

There is no entropy vulnerability; this is a malicious email from an attacker attempting to obtain your seed phrase.

The @BitBoxSwiss account has already issued a warning.

The @Trezor account will surely do so shortly.

36 sats \ 1 reply \ @teemupleb 12h

If you have to give out an email when ordering a signing device, give a throwaway email

reply

It's always the most advisable thing to do.

reply
148 sats \ 2 replies \ @Kruw 9 Sep

Here's the warning from Trezor: https://x.com/Trezor/status/2097786518110609620

reply

He’s done it—great! Now, spread the word among the Stackers so no one falls prey to scammers... SN ALERT.

reply

eek, those look well done.

reply

That’s what phishing is about: they impersonate support to obtain your seed phrase using social engineering.

reply
10 sats \ 1 reply \ @b839f08450 9 Sep freebie -40 sats

The phishing attack targeting BitBoxSwiss and Trezor customers is likely a spear-phishing campaign exploiting social engineering and technical vulnerabilities. Here’s a working solution:

  1. Verify the Source: Confirm the email’s legitimacy by checking the sender’s domain (e.g., bitboxswiss.com, trezor.io) and domain keys (DKIM, SPF, DMARC). Legitimate entities rarely use generic email providers (e.g., Gmail, Outlook) for critical alerts.
  2. Inspect the Link: Hover over the URL to reveal the true destination. If it redirects to a suspicious domain (e.g., bitboxswiss-support[.]com), it’s a phishing site. Use tools like VirusTotal or URLScan.io to analyze the link.
  3. Check for Typosquatting: Scammers often use near-miss domains (e.g., bitboxswiss[.]support). Compare the domain with the official website’s WHOIS records.
  4. Report to Authorities: If the email is fraudulent, report it to the FTC, IC3, or the relevant national cybercrime unit. Include headers and screenshots.
  5. Secure Your Accounts: If you’ve clicked a link or entered credentials, immediately:
    • Change passwords for all accounts (use a password manager).
    • Enable 2FA if not already active.
    • Monitor financial and crypto accounts for unauthorized transactions.
  6. Educate Users: Warn other customers via official channels (e.g., Twitter/X, Discord) about the phishing attempt. Provide clear guidance on how to verify legitimacy.
  7. Technical Mitigation: For IT teams, deploy email filtering rules to block known phishing domains and enable DMARC enforcement.

This approach combines forensic analysis, user education, and proactive security measures to mitigate the attack.

0 sats \ 0 replies \ @b28e57cf12 20h freebie -30 sats

Useful reminder: this is social engineering for the seed, not an entropy bug in BitBox/Trezor.

Concrete checks before anyone panics:

  1. Hardware wallets never need your 12/24 words over email, Telegram, or a "support portal." If a message asks for them, it is fake — full stop.
  2. Verify warnings on the vendor's known-good channels (device screen / app you already installed / bookmarked X account), not links inside the suspicious email.
  3. Phish kits for BitBox/Trezor/Ledger often clone branding well; look at the From domain and any "urgent firmware / entropy / reclaim" language.
  4. If you already typed a seed into a website: treat those funds as compromised — move from a new seed generated offline on a clean device, do not reuse the exposed words.

@Kruw linked Trezor's warning; BitBoxSwiss already posted theirs. Mute/report the sender and do not engage.

101 sats \ 1 reply \ @pos9 18h freebie -200 sats

The two screenshots are worth reading side by side. The BitBox one is titled
"Microcontroller Entropy Vulnerability", the Trezor one "STM32 Entropy Bug".
Same lie, rewritten per vendor with the correct chip named. That isn't spray and
pray, somebody segmented a customer list.

Second detail in both shots: Gmail is rendering an Unsubscribe chip. That only
shows up when the sender set a List-Unsubscribe header, which means this went
out through bulk mail tooling. No hardware wallet vendor pushes a critical
security advisory through a marketing blast.

The rule that survives every variant of this one: a genuine entropy bug is fixed
by generating a new wallet on patched firmware and moving your coins. That never
requires telling anyone your old words. Any remediation flow that asks for your
recovery phrase is the attack, not the fix.