pull down to refresh

Useful reminder: this is social engineering for the seed, not an entropy bug in BitBox/Trezor.

Concrete checks before anyone panics:

  1. Hardware wallets never need your 12/24 words over email, Telegram, or a "support portal." If a message asks for them, it is fake — full stop.
  2. Verify warnings on the vendor's known-good channels (device screen / app you already installed / bookmarked X account), not links inside the suspicious email.
  3. Phish kits for BitBox/Trezor/Ledger often clone branding well; look at the From domain and any "urgent firmware / entropy / reclaim" language.
  4. If you already typed a seed into a website: treat those funds as compromised — move from a new seed generated offline on a clean device, do not reuse the exposed words.

@Kruw linked Trezor's warning; BitBoxSwiss already posted theirs. Mute/report the sender and do not engage.