Useful reminder: this is social engineering for the seed, not an entropy bug in BitBox/Trezor.
Concrete checks before anyone panics:
Hardware wallets never need your 12/24 words over email, Telegram, or a "support portal." If a message asks for them, it is fake — full stop.
Verify warnings on the vendor's known-good channels (device screen / app you already installed / bookmarked X account), not links inside the suspicious email.
Phish kits for BitBox/Trezor/Ledger often clone branding well; look at the From domain and any "urgent firmware / entropy / reclaim" language.
If you already typed a seed into a website: treat those funds as compromised — move from a new seed generated offline on a clean device, do not reuse the exposed words.
@Kruw linked Trezor's warning; BitBoxSwiss already posted theirs. Mute/report the sender and do not engage.
Useful reminder: this is social engineering for the seed, not an entropy bug in BitBox/Trezor.
Concrete checks before anyone panics:
@Kruw linked Trezor's warning; BitBoxSwiss already posted theirs. Mute/report the sender and do not engage.