1Sem.·

WARNING: Phishing!

If you've just received an email from $BTC (+0,27 %) from Bitbox, Trezor, CoinTracking, or others, please don’t click on anything and under no circumstances enter your 12- or 24-word recovery phrase anywhere!


I’ve received two emails myself from Bitbox and CoinTracking. Both appeared to come from legitimate sender addresses. They were put together very, very professionally... please be careful😘


https://x.com/blocktrainer/status/2097777779056201834

previw image
39
19 Commentaires

image de profil
Thanks for the info
3
image de profil
Could this be related to the "pocket" incident—that the perpetrators obtained the email addresses from that incident?
3
image de profil
@Carsten1970 That's an interesting theory. I also received the notification about Pocket. I actually use Pocket for shopping, too.
1
image de profil
@paul_finesse_ According to Pocket, my data has also been compromised, and I've made purchases through Pocket before. That's why I had this idea.
1
image de profil
@Carsten1970 I had thought of something like that, too. Or the 21Bitcoin incident—email addresses were stolen there as well...

But it seems as though the shared email service Brevo has been compromised:

https://www.blocktrainer.de/blog/phishing-welle-gegen-bitcoin-nutzer-gefaelschte-newsletter-von-bitbox-trezor-cointracking
1
image de profil
@stefan_21 That sounds plausible, too
image de profil
@Carsten1970 Are you still shopping at Pocket, or did you change your email address as well?
image de profil
@paul_finesse_ I haven't shopped at Pocket in a long time. I've been using Strike for quite a while now—mainly because of the cost.
1
image de profil
It was well done overall, but the fact that the email from "Bitbox" was in English immediately made me suspicious. Their newsletters are usually always in German.
2
image de profil
I just got one too. The sender appears to be bitbox.swiss.

That email is really well done.

Always keep your eyes open.
1
image de profil
@Carsten1970 I got that, too
image de profil
I only noticed it because of the URL in the link. Curious as I am, I clicked on it anyway (of course, from a device that wasn't connected to my coins). It actually asks you to enter your seed phrase right in the browser.

Right above the link in the email

"NEVER enter your recovery phrase on a website or share it with anyone, and only check for updates on official BitBox channels."

I'm sure some people do it anyway.
1
image de profil
@DonkeyInvestor Little donkey, what a relief that we have "biological cyber security" up and running in your stable… we're totally safe there!! 🫢
1
image de profil
@DonkeyInvestor Yeah, I noticed it through the link, too. And it seemed weird to me that it would be a hardware problem that only occurs with certain firmware versions 😅
1
image de profil
@stefan_21 and that the email was in English. Bitbox usually writes to me in German
1
image de profil
Nothing on my side with Tangem 😴
image de profil
@pelo That's great. But please be aware that with Tangem, you're exposed to risks that are quite different from those associated with a Bitbox or Trezor. Tangem doesn't have a display. As a result, you don't know exactly what you're signing with your hardware wallet. You have to rely on what your smartphone screen tells you. And that could always be wrong. Tangem is therefore more comparable to a software wallet than a hardware wallet.
1
image de profil
@stefan_21 I agree that’s the negative part but in the same time u have no update firmware to do so u reduce the risk of a malware
1
image de profil
@pelo Fair point, no firmware updates does close one attack vector. But the malware you should worry about isn't on the card, it's on the phone. With Tangem, the phone is your only screen: the app builds the transaction, shows it to you, and the card signs whatever it gets. If the phone is compromised, the card can't protect you because it has no way to show you what it's actually signing. A Bitbox or Trezor verifies the address and amount on its own display, independent of the computer or phone.

Also, "no updates" cuts both ways - if a bug is ever found in the card's firmware, it can never be patched.

Not saying Tangem is useless, I just wouldn't treat it as equivalent to a real hardware wallet for larger amounts :)
1
Participez à la conversation