Bitcoin Forum
May 04, 2024, 03:13:44 AM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: « 1 [2]  All
  Print  
Author Topic: making fake HW wallets(will we see this scam next)??  (Read 311 times)
ben19850 (OP)
Newbie
*
Offline Offline

Activity: 19
Merit: 3


View Profile
January 30, 2022, 04:26:19 PM
Last edit: January 31, 2022, 06:34:11 PM by ben19850
 #21

If I understand the OP correctly, he is asking if it would be possible to create a wallet that always displays one or more receiving addresses of the hacker independent of what seed + seed extension the victim is using. The software of such a device would have no role at all, and would work as a regular hardware wallet where you are shown a seed to write down. But no matter what seed or passphrase you use, the device ends up displaying the same receiving addresses that ultimately leads to the victim making transactions to addresses that belong to the hacker. Is that it?

I don't think this is impossible.  

YES pretty much

i know the HW would need a hard mod(ledgers easliy known for this)

on top of that a softwear mod to falsley display BTC wallet address that the scammer has control of
Be very wary of relying on JavaScript for security on crypto sites. The site can change the JavaScript at any time unless you take unusual precautions, and browsers are not generally known for their airtight security.
Advertised sites are not endorsed by the Bitcoin Forum. They may be unsafe, untrustworthy, or illegal in your jurisdiction.
1714792424
Hero Member
*
Offline Offline

Posts: 1714792424

View Profile Personal Message (Offline)

Ignore
1714792424
Reply with quote  #2

1714792424
Report to moderator
DaveF
Legendary
*
Offline Offline

Activity: 3472
Merit: 6259


Crypto Swap Exchange


View Profile WWW
January 30, 2022, 04:43:29 PM
 #22

The issue is that you would have to:

1) Design and build a fake hardware wallet
2) Make software that will work with it
3) Sell it / give it away to have people use it
4) Have the source complex enough to get away with people not noticing what you are doing.

It's much quicker and easier to setup a scam coin or fake electrum site and drive people to it or a bad link to metamask or something else.

Could it be done? Yes.
Would it be worth it? Probably not.
If money was no object and you have a specific person / target in mind could you do do it? Yes

-Dave

█▀▀▀











█▄▄▄
▀▀▀▀▀▀▀▀▀▀▀
e
▄▄▄▄▄▄▄▄▄▄▄
█████████████
████████████▄███
██▐███████▄█████▀
█████████▄████▀
███▐████▄███▀
████▐██████▀
█████▀█████
███████████▄
████████████▄
██▄█████▀█████▄
▄█████████▀█████▀
███████████▀██▀
████▀█████████
▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀
c.h.
▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄
▀▀▀█











▄▄▄█
▄██████▄▄▄
█████████████▄▄
███████████████
███████████████
███████████████
███████████████
███░░█████████
███▌▐█████████
█████████████
███████████▀
██████████▀
████████▀
▀██▀▀
dkbit98
Legendary
*
Offline Offline

Activity: 2226
Merit: 7117



View Profile WWW
January 31, 2022, 03:45:49 PM
 #23

Design and build a fake hardware wallet
This already happened before with fake ledger wallet that was looking exactly the same from outside, but from inside it was different and it was pre-loaded with fake ledger software already.
Nobody knows exactly how many people received this devices but we know that scammers used ledger amateurs leaked database with home addresses information.
With recent stupid changes ledger is making it's not even possible to verify if your device is genuine because they are gluing pcb with battery  Roll Eyes

It's much quicker and easier to setup a scam coin or fake electrum site and drive people to it or a bad link to metamask or something else.
Those are cheap phishing scam and fake tech support that gets recycled all the time.
There are different level of scammers, lowlife and upper class, but biggest scam would be to just infiltrate one STM32 chip manufacturer that is used in most hardware wallets.

.
.HUGE.
▄██████████▄▄
▄█████████████████▄
▄█████████████████████▄
▄███████████████████████▄
▄█████████████████████████▄
███████▌██▌▐██▐██▐████▄███
████▐██▐████▌██▌██▌██▌██
█████▀███▀███▀▐██▐██▐█████

▀█████████████████████████▀

▀███████████████████████▀

▀█████████████████████▀

▀█████████████████▀

▀██████████▀▀
█▀▀▀▀











█▄▄▄▄
▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀
.
CASINSPORTSBOOK
▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄
▀▀▀▀█











▄▄▄▄█
m2017
Legendary
*
Offline Offline

Activity: 1806
Merit: 1304


keep walking, Johnnie


View Profile
February 01, 2022, 01:51:35 PM
 #24

Design and build a fake hardware wallet
This already happened before with fake ledger wallet that was looking exactly the same from outside, but from inside it was different and it was pre-loaded with fake ledger software already.
Nobody knows exactly how many people received this devices but we know that scammers used ledger amateurs leaked database with home addresses information.
With recent stupid changes ledger is making it's not even possible to verify if your device is genuine because they are gluing pcb with battery  Roll Eyes

Do I understand correctly that there have already been cases with the substitution of fake ledger wallets? This is the first time I hear about it. Can you tell me where I can read about this incident? Were there people who lost their funds because of this?

.BEST..CHANGE.███████████████
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
███████████████
..BUY/ SELL CRYPTO..
o_e_l_e_o
In memoriam
Legendary
*
Offline Offline

Activity: 2268
Merit: 18509


View Profile
February 01, 2022, 02:03:54 PM
 #25

Do I understand correctly that there have already been cases with the substitution of fake ledger wallets? This is the first time I hear about it. Can you tell me where I can read about this incident? Were there people who lost their funds because of this?
You can read about it here: https://www.reddit.com/r/ledgerwallet/comments/o154gz/package_from_ledger_is_this_legit/

I'm not sure if anyone has lost funds to this attack.

Essentially it involves replacing the hardware inside a Ledger device with different hardware which causes the hardware wallet to behave like a simple mass storage device (essentially a USB drive). The scammers mail out these devices along with instructions telling people to connect their "hardware wallet", open the software on the mass storage device, and enter their seed phrase, all under the guise of "securing their coins" or some similar bullshit story. As soon as you enter your seed phrase, it is sent to the scammers and your coins are stolen.

So yes, while fake Ledger wallets exist in the wild (along with fake devices of several other brands of hardware wallets), they do not behave the same as a genuine hardware wallet and you have to be very naive to fall for them and ignore all the real advice, guides, and warnings which come with your genuine device and are on all the relevant hardware wallet manufacturer websites.
dkbit98
Legendary
*
Offline Offline

Activity: 2226
Merit: 7117



View Profile WWW
February 01, 2022, 04:10:25 PM
 #26

Do I understand correctly that there have already been cases with the substitution of fake ledger wallets? This is the first time I hear about it. Can you tell me where I can read about this incident? Were there people who lost their funds because of this?

Yeah it happened and I have been writing all about that last year in one of my topics.
Packaging and case looked like original, they even had plastic cover (not that hard to make even at home), fake packaging bag, so newbies could fall for this trap easy.
Only difference was with fake instructions, inside of device pcb was different and fake software that was pre-loaded on device.
Experienced users and previous ledger owners would probably notice suspicious scam device and report it like one of them did.

 

Fake Instructions is asking users connect the Ledger to their computer, than import recovery phrase from their old device, and that is sent to the attackers who imports it on their own devices and steal crypto.



Guy who received this fake ledger opened the device that was later compared with original device and you can see the clear difference inside both front and back as well as some sloppy soldering work.

They added a flash drive inside Ledger case and wired it to the USB connector with the purpose to be used for malware delivery to attackers.

 

.
.HUGE.
▄██████████▄▄
▄█████████████████▄
▄█████████████████████▄
▄███████████████████████▄
▄█████████████████████████▄
███████▌██▌▐██▐██▐████▄███
████▐██▐████▌██▌██▌██▌██
█████▀███▀███▀▐██▐██▐█████

▀█████████████████████████▀

▀███████████████████████▀

▀█████████████████████▀

▀█████████████████▀

▀██████████▀▀
█▀▀▀▀











█▄▄▄▄
▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀
.
CASINSPORTSBOOK
▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄
▀▀▀▀█











▄▄▄▄█
ChiBitCTy
Legendary
*
Offline Offline

Activity: 2254
Merit: 3007



View Profile
February 01, 2022, 04:34:27 PM
 #27

I could see this happening.  Take a look at these fake Trezors- https://bitcointalk.org/index.php?topic=5227930.0


███████████████████████████
███████▄████████████▄██████
████████▄████████▄████████
███▀█████▀▄███▄▀█████▀███
█████▀█▀▄██▀▀▀██▄▀█▀█████
███████▄███████████▄███████
███████████████████████████
███████▀███████████▀███████
████▄██▄▀██▄▄▄██▀▄██▄████
████▄████▄▀███▀▄████▄████
██▄███▀▀█▀██████▀█▀███▄███
██▀█▀████████████████▀█▀███
███████████████████████████
.
.Duelbits.
..........UNLEASH..........
THE ULTIMATE
GAMING EXPERIENCE
DUELBITS
FANTASY
SPORTS
████▄▄█████▄▄
░▄████
███████████▄
▐███
███████████████▄
███
████████████████
███
████████████████▌
███
██████████████████
████████████████▀▀▀
███████████████▌
███████████████▌
████████████████
████████████████
████████████████
████▀▀███████▀▀
.
▬▬
VS
▬▬
████▄▄▄█████▄▄▄
░▄████████████████▄
▐██████████████████▄
████████████████████
████████████████████▌
█████████████████████
███████████████████
███████████████▌
███████████████▌
████████████████
████████████████
████████████████
████▀▀███████▀▀
/// PLAY FOR  FREE  ///
WIN FOR REAL
..PLAY NOW..
m2017
Legendary
*
Offline Offline

Activity: 1806
Merit: 1304


keep walking, Johnnie


View Profile
February 02, 2022, 06:12:40 AM
 #28

Do I understand correctly that there have already been cases with the substitution of fake ledger wallets? This is the first time I hear about it. Can you tell me where I can read about this incident? Were there people who lost their funds because of this?
You can read about it here: https://www.reddit.com/r/ledgerwallet/comments/o154gz/package_from_ledger_is_this_legit/
Thank you for sharing this link and comments.


Do I understand correctly that there have already been cases with the substitution of fake ledger wallets? This is the first time I hear about it. Can you tell me where I can read about this incident? Were there people who lost their funds because of this?

Yeah it happened and I have been writing all about that last year in one of my topics.
Packaging and case looked like original, they even had plastic cover (not that hard to make even at home), fake packaging bag, so newbies could fall for this trap easy.
Only difference was with fake instructions, inside of device pcb was different and fake software that was pre-loaded on device.
Experienced users and previous ledger owners would probably notice suspicious scam device and report it like one of them did.

 

 

Thanks for posting this info here. This will not only satisfy my curiosity, but may be useful for future Ledger buyers.

I am surprised by the quality of the blue film packaging. It immediately catches the eye and looks sloppy, poor quality and suspicious.

The person who received this device did not order it, but received it just like that? Those, this should already be alarming in such cases: you did not buy or order, but you received a device.

.BEST..CHANGE.███████████████
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
███████████████
..BUY/ SELL CRYPTO..
Pmalek
Legendary
*
Offline Offline

Activity: 2758
Merit: 7130



View Profile
February 02, 2022, 10:33:10 AM
 #29

The person who received this device did not order it, but received it just like that? Those, this should already be alarming in such cases: you did not buy or order, but you received a device.
People who fall for scams, don't usually think straight or use common sense.

The information that came with those devices instructed the victims to use these brand-new devices because the old ones (the genuine ones) should no longer be trusted and aren't good enough. Something like that. They got info about their victims through the data leaks. But if you have a genuine copy of Ledger Live, you wouldn't be able to pair it with this fake device. Because only genuine Ledger HWs can be connected to Ledger servers on Ledger Live. You have to use their fake software. Essentially, this is the same thing as downloading or installing a fake Electrum wallet. Only this time, a hardware wallet is part of the deal. 

Someone who thinks straight would probably want to doublecheck this. It's only logical that Ledger would announce to their community that they are sending affected parties brand-new and improved devices. So you would check their website, blog, social media, etc. to find this information.

I fear what could happen if medical records of those who have been vaccinated leaked somewhere. I can only imagine how many people would inject themselves if they received a package with a vaccine instructing them to inject it in their leg, arm, buttocks, or whatever because the vaccines they were given previously have been proven to not be effective enough. This new self-injecting one we created is state of the line. Roll Eyes

.
.BLACKJACK ♠ FUN.
█████████
██████████████
████████████
█████████████████
████████████████▄▄
░█████████████▀░▀▀
██████████████████
░██████████████
████████████████
░██████████████
████████████
███████████████░██
██████████
CRYPTO CASINO &
SPORTS BETTING
▄▄███████▄▄
▄███████████████▄
███████████████████
█████████████████████
███████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
███████████████████████
█████████████████████
███████████████████
▀███████████████▀
█████████
.
o_e_l_e_o
In memoriam
Legendary
*
Offline Offline

Activity: 2268
Merit: 18509


View Profile
February 02, 2022, 11:37:33 AM
 #30

I am surprised by the quality of the blue film packaging. It immediately catches the eye and looks sloppy, poor quality and suspicious.
Everything about the package is sloppy. If you look at the photo of the letter which came with it, it is full of informal language and grammatical errors which you would not expect from an official document. The same goes for the set up guide.

The person who received this device did not order it, but received it just like that? Those, this should already be alarming in such cases: you did not buy or order, but you received a device.
They were targeted because their details were part of the Ledger database hack, so the attacker knew their name and address and knew they owned a Ledger device. But yes, receiving anything you aren't expecting through the mail should be a red flag. Just as you should never plug in a random USB drive you find or are given, you should never use a hardware wallet you find or are given - only use one you bought yourself directly from the manufacturer.
dkbit98
Legendary
*
Offline Offline

Activity: 2226
Merit: 7117



View Profile WWW
February 02, 2022, 08:57:32 PM
 #31

I could see this happening.  Take a look at these fake Trezors
This mini-trezors are not available anymore and they used different hardware components, but I don't think they were a scam and they used exact same software/firmware like original Trezor.
It was just a smaller Russian version on Trezor wallet and it would be cool to have it as a collectible, nothing more.
There are even DIY wallets with full instructions how to make your own device and 3d print the case, so it's not that hard.

Someone recently reported that many people are selling old and broken Ledger hardware wallets for cheap on ebay and other websites.
Maybe people buy them for spare parts but we know that ledger sold millions of this devices and they are all around the world.
It would not be so hard for scammers to purchase those device, refurbish them, make modifications and load their malware software.
Maybe they come in box packages, but they can always make new boxes and do better job in adding foil over them.



.
.HUGE.
▄██████████▄▄
▄█████████████████▄
▄█████████████████████▄
▄███████████████████████▄
▄█████████████████████████▄
███████▌██▌▐██▐██▐████▄███
████▐██▐████▌██▌██▌██▌██
█████▀███▀███▀▐██▐██▐█████

▀█████████████████████████▀

▀███████████████████████▀

▀█████████████████████▀

▀█████████████████▀

▀██████████▀▀
█▀▀▀▀











█▄▄▄▄
▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀
.
CASINSPORTSBOOK
▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄
▀▀▀▀█











▄▄▄▄█
ChiBitCTy
Legendary
*
Offline Offline

Activity: 2254
Merit: 3007



View Profile
February 02, 2022, 09:29:12 PM
 #32

I could see this happening.  Take a look at these fake Trezors
This mini-trezors are not available anymore and they used different hardware components, but I don't think they were a scam and they used exact same software/firmware like original Trezor.
It was just a smaller Russian version on Trezor wallet and it would be cool to have it as a collectible, nothing more.
There are even DIY wallets with full instructions how to make your own device and 3d print the case, so it's not that hard.

Someone recently reported that many people are selling old and broken Ledger hardware wallets for cheap on ebay and other websites.
Maybe people buy them for spare parts but we know that ledger sold millions of this devices and they are all around the world.
It would not be so hard for scammers to purchase those device, refurbish them, make modifications and load their malware software.
Maybe they come in box packages, but they can always make new boxes and do better job in adding foil over them.




But do you know if anyone actually did a deep dive in to these things to see if there was any hidden stuff?  Would there be a way to easily hide malicious stuff inside these things?  This is of course why I preach to all my friends/clients to buy from the manufacturer directly.  ( I would def love to  have one of these fake trezor's as a collectible!)

███████████████████████████
███████▄████████████▄██████
████████▄████████▄████████
███▀█████▀▄███▄▀█████▀███
█████▀█▀▄██▀▀▀██▄▀█▀█████
███████▄███████████▄███████
███████████████████████████
███████▀███████████▀███████
████▄██▄▀██▄▄▄██▀▄██▄████
████▄████▄▀███▀▄████▄████
██▄███▀▀█▀██████▀█▀███▄███
██▀█▀████████████████▀█▀███
███████████████████████████
.
.Duelbits.
..........UNLEASH..........
THE ULTIMATE
GAMING EXPERIENCE
DUELBITS
FANTASY
SPORTS
████▄▄█████▄▄
░▄████
███████████▄
▐███
███████████████▄
███
████████████████
███
████████████████▌
███
██████████████████
████████████████▀▀▀
███████████████▌
███████████████▌
████████████████
████████████████
████████████████
████▀▀███████▀▀
.
▬▬
VS
▬▬
████▄▄▄█████▄▄▄
░▄████████████████▄
▐██████████████████▄
████████████████████
████████████████████▌
█████████████████████
███████████████████
███████████████▌
███████████████▌
████████████████
████████████████
████████████████
████▀▀███████▀▀
/// PLAY FOR  FREE  ///
WIN FOR REAL
..PLAY NOW..
Pmalek
Legendary
*
Offline Offline

Activity: 2758
Merit: 7130



View Profile
February 03, 2022, 09:47:52 AM
 #33

Someone recently reported that many people are selling old and broken Ledger hardware wallets for cheap on ebay and other websites.
Maybe people buy them for spare parts but we know that ledger sold millions of this devices and they are all around the world.
Even that's not really needed because based on the info I received from Ledger's support team when I sent them those fake emails pretending I have various problems with the wallets, they are willing to replace broken devices even if they are out of warranty.

But do you know if anyone actually did a deep dive in to these things to see if there was any hidden stuff?  Would there be a way to easily hide malicious stuff inside these things?
If they are based on Trezor's open-source code, you can check it yourself and everyone else could as well. But most people don't know how to do that. Open-source doesn't make those Russian Trezors safe, it just means that the code can be independently verified. So if it has something that shouldn't be there, it could be discovered. 

.
.BLACKJACK ♠ FUN.
█████████
██████████████
████████████
█████████████████
████████████████▄▄
░█████████████▀░▀▀
██████████████████
░██████████████
████████████████
░██████████████
████████████
███████████████░██
██████████
CRYPTO CASINO &
SPORTS BETTING
▄▄███████▄▄
▄███████████████▄
███████████████████
█████████████████████
███████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
███████████████████████
█████████████████████
███████████████████
▀███████████████▀
█████████
.
m2017
Legendary
*
Offline Offline

Activity: 1806
Merit: 1304


keep walking, Johnnie


View Profile
February 03, 2022, 01:46:26 PM
 #34

I could see this happening.  Take a look at these fake Trezors- https://bitcointalk.org/index.php?topic=5227930.0



I see Trezor has a new (for 2020) line of wallets  Smiley. Forgive me for this, but I am amused by the appearance of these devices and the creativity of the creators of the fake device. It was necessary to come up with a "Mini" for these Frankenstein freaks  Smiley.  They look like cheap chinese toys of the lowest quality.

P.S. I learned about these crafts only from this post and for me this is the news of the day. It would be nice to periodically remind about such fakes, as topics about them slide down and disappear from the field of view of their possible victims. And so, at least there is a chance that someone will see a warning about this and will stop them from doing stupid things.

.BEST..CHANGE.███████████████
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
███████████████
..BUY/ SELL CRYPTO..
dkbit98
Legendary
*
Offline Offline

Activity: 2226
Merit: 7117



View Profile WWW
February 03, 2022, 03:17:33 PM
 #35

But do you know if anyone actually did a deep dive in to these things to see if there was any hidden stuff?
What I found when I did big research of hardware wallets is that Buterino didn't use any malicious stuff in their wallets, it was similar components like in original trezor.
I don't have any of this mini-trezor devices myself so I can't confirm and be totally sure about this, and who knows what could happen after they stopped creating this devices.
I would not suggest using this devices as firmware is outdated, but I would be interested to hear if someone from bitcointalk forum owns them as collectible.

This is of course why I preach to all my friends/clients to buy from the manufacturer directly.  ( I would def love to  have one of these fake trezor's as a collectible!)
Maybe it's best if they don't buy them at all now.
Honestly, I would suggest anyone not to buy any Trezor wallets until they add open source secure element and fix issues they have (they are working on this).
I would never suggest ledger because they are closed source and they have countless issues with their devices, especially nono x.
Buying good used laptop and using it only offline for crypto wallets or with Tails OS is a good alternative, and you won't leak your data to crypto scammers.




.
.HUGE.
▄██████████▄▄
▄█████████████████▄
▄█████████████████████▄
▄███████████████████████▄
▄█████████████████████████▄
███████▌██▌▐██▐██▐████▄███
████▐██▐████▌██▌██▌██▌██
█████▀███▀███▀▐██▐██▐█████

▀█████████████████████████▀

▀███████████████████████▀

▀█████████████████████▀

▀█████████████████▀

▀██████████▀▀
█▀▀▀▀











█▄▄▄▄
▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀
.
CASINSPORTSBOOK
▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄
▀▀▀▀█











▄▄▄▄█
Pages: « 1 [2]  All
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!