pull down to refresh

The two screenshots are worth reading side by side. The BitBox one is titled
"Microcontroller Entropy Vulnerability", the Trezor one "STM32 Entropy Bug".
Same lie, rewritten per vendor with the correct chip named. That isn't spray and
pray, somebody segmented a customer list.

Second detail in both shots: Gmail is rendering an Unsubscribe chip. That only
shows up when the sender set a List-Unsubscribe header, which means this went
out through bulk mail tooling. No hardware wallet vendor pushes a critical
security advisory through a marketing blast.

The rule that survives every variant of this one: a genuine entropy bug is fixed
by generating a new wallet on patched firmware and moving your coins. That never
requires telling anyone your old words. Any remediation flow that asks for your
recovery phrase is the attack, not the fix.

They're details, but in the rush you don't see them and you fall into the trap; not all users have the same knowledge.

reply