Bitcoin Forum
May 13, 2024, 03:31:49 PM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: [1]
  Print  
Author Topic: Trezor phishing scam is in progress  (Read 161 times)
Pmalek (OP)
Legendary
*
Offline Offline

Activity: 2758
Merit: 7138



View Profile
February 28, 2023, 06:23:00 PM
Merited by DdmrDdmr (4), SFR10 (1), TryNinja (1), dkbit98 (1), Rikafip (1), ajiz138 (1), Dave1 (1)
 #1

Trezor warned its community about an ongoing phishing scam a few hours ago.
According to the company's information, scammers contact users via SMS, email, and even phone. Potential victims are told that their Trezor Suite has been breached and is vulnerable. The scammers probably instruct users to download fake apps to steal their seeds and cryptocurrencies.

- Don't fall for it because it's fake!
- If you are a Trezor user, don't click on unknown links and answer calls from unknown numbers.
It's the oldest trick in the book.

Trezor states they have no information about a data breach on their end. We should know more in the next few days if something bad has happened.



If you are a Trezor user, did you receive any emails, SMS, or calls from scammers? 


Source:
https://twitter.com/Trezor/status/1630526933199998977 

.
.BLACKJACK ♠ FUN.
█████████
██████████████
████████████
█████████████████
████████████████▄▄
░█████████████▀░▀▀
██████████████████
░██████████████
████████████████
░██████████████
████████████
███████████████░██
██████████
CRYPTO CASINO &
SPORTS BETTING
▄▄███████▄▄
▄███████████████▄
███████████████████
█████████████████████
███████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
███████████████████████
█████████████████████
███████████████████
▀███████████████▀
█████████
.
1715614309
Hero Member
*
Offline Offline

Posts: 1715614309

View Profile Personal Message (Offline)

Ignore
1715614309
Reply with quote  #2

1715614309
Report to moderator
1715614309
Hero Member
*
Offline Offline

Posts: 1715614309

View Profile Personal Message (Offline)

Ignore
1715614309
Reply with quote  #2

1715614309
Report to moderator
1715614309
Hero Member
*
Offline Offline

Posts: 1715614309

View Profile Personal Message (Offline)

Ignore
1715614309
Reply with quote  #2

1715614309
Report to moderator
Unlike traditional banking where clients have only a few account numbers, with Bitcoin people can create an unlimited number of accounts (addresses). This can be used to easily track payments, and it improves anonymity.
Advertised sites are not endorsed by the Bitcoin Forum. They may be unsafe, untrustworthy, or illegal in your jurisdiction.
1715614309
Hero Member
*
Offline Offline

Posts: 1715614309

View Profile Personal Message (Offline)

Ignore
1715614309
Reply with quote  #2

1715614309
Report to moderator
1715614309
Hero Member
*
Offline Offline

Posts: 1715614309

View Profile Personal Message (Offline)

Ignore
1715614309
Reply with quote  #2

1715614309
Report to moderator
1715614309
Hero Member
*
Offline Offline

Posts: 1715614309

View Profile Personal Message (Offline)

Ignore
1715614309
Reply with quote  #2

1715614309
Report to moderator
DdmrDdmr
Legendary
*
Offline Offline

Activity: 2310
Merit: 10759


There are lies, damned lies and statistics. MTwain


View Profile WWW
February 28, 2023, 06:56:49 PM
Last edit: February 28, 2023, 07:17:36 PM by DdmrDdmr
Merited by Pmalek (2), TryNinja (1)
 #2

If you follow the phishing link, it goes on to show the following "warning":



If you then proceed, it the goes and .. surprise .. yep, it asks you for your seed:


It doesn’t really go any further, but it obviously logs whatever you type.


What now remains to be seen is what the actual origin of the data for the phishing campaign is, and whether it is random (but based on a crypto related user list) or specific to Trezor.

Edit:
Another option I was toying around with, is that some data could be originated in one of the prio mailchimp leaks that affected Trezor. Though I believe they mentioned only emails were leaked, it only takes a bit of effort for someone to cross a couple of rough databases by email and start to associate some registers with a phone number in addition to the email.
dkbit98
Legendary
*
Offline Offline

Activity: 2226
Merit: 7149



View Profile WWW
February 28, 2023, 07:08:47 PM
 #3

Scammers never sleep  Roll Eyes
Few day ago in one of my temporary email addresses I received this two messages from fake Trezor with similar content, but it was obvious to me so I didn't click anything and I permanently deleted both of them.
I think this is not connected with any Trezor leak, but to some other crypto service... so they are using any crypto leak hoping that people are using hardware wallets.

█████████████████████████
████▐██▄█████████████████
████▐██████▄▄▄███████████
████▐████▄█████▄▄████████
████▐█████▀▀▀▀▀███▄██████
████▐███▀████████████████
████▐█████████▄█████▌████
████▐██▌█████▀██████▌████
████▐██████████▀████▌████
█████▀███▄█████▄███▀█████
███████▀█████████▀███████
██████████▀███▀██████████
█████████████████████████
.
BC.GAME
▄▄░░░▄▀▀▄████████
▄▄▄
██████████████
█████░░▄▄▄▄████████
▄▄▄▄▄▄▄▄▄██▄██████▄▄▄▄████
▄███▄█▄▄██████████▄████▄████
███████████████████████████▀███
▀████▄██▄██▄░░░░▄████████████
▀▀▀█████▄▄▄███████████▀██
███████████████████▀██
███████████████████▄██
▄███████████████████▄██
█████████████████████▀██
██████████████████████▄
.
..CASINO....SPORTS....RACING..
█░░░░░░█░░░░░░█
▀███▀░░▀███▀░░▀███▀
▀░▀░░░░▀░▀░░░░▀░▀
░░░░░░░░░░░░
▀██████████
░░░░░███░░░░
░░█░░░███▄█░░░
░░██▌░░███░▀░░██▌
░█░██░░███░░░█░██
░█▀▀▀█▌░███░░█▀▀▀█▌
▄█▄░░░██▄███▄█▄░░▄██▄
▄███▄
░░░░▀██▄▀


▄▄████▄▄
▄███▀▀███▄
██████████
▀███▄░▄██▀
▄▄████▄▄░▀█▀▄██▀▄▄████▄▄
▄███▀▀▀████▄▄██▀▄███▀▀███▄
███████▄▄▀▀████▄▄▀▀███████
▀███▄▄███▀░░░▀▀████▄▄▄███▀
▀▀████▀▀████████▀▀████▀▀
ajiz138
Hero Member
*****
Offline Offline

Activity: 1498
Merit: 785



View Profile WWW
February 28, 2023, 07:21:52 PM
 #4

I am a Trezor user, although I didn't get any messages from email, SMS, or telephone. If someone asks for the seeds, then obviously it's a fraud, because what we know is that we ourselves have to know the seeds.

I'm pretty sure we see this fraudulent trick often, but when you tell it to other people, especially those who don't follow the official trezor notification, it's quite helpful for those who have this hardware.

It's no wonder that scammers have many ways to carry out their actions, one of which is that we must remain vigilant and never give seeds to anyone.

███████████████████████████
███████▄████████████▄██████
████████▄████████▄████████
███▀█████▀▄███▄▀█████▀███
█████▀█▀▄██▀▀▀██▄▀█▀█████
███████▄███████████▄███████
███████████████████████████
███████▀███████████▀███████
████▄██▄▀██▄▄▄██▀▄██▄████
████▄████▄▀███▀▄████▄████
██▄███▀▀█▀██████▀█▀███▄███
██▀█▀████████████████▀█▀███
███████████████████████████
.
.Duelbits.
▄▄█▄▄░░▄▄█▄▄░░▄▄█▄▄
███░░░░███░░░░███
░░░░░░░░░░░░░
░░░░░░░░░░░░
▀██████████
░░░░░███░░░░
░░░░░███▄█░░░
░░██▌░░███░▀░░██▌
█░██░░███░░░██
█▀▀▀█▌░███░░█▀▀▀█▌
▄█▄░░░██▄███▄█▄░░▄██▄
▄███▄
░░░░▀██▄▀
.
REGIONAL
SPONSOR
███▀██▀███▀█▀▀▀▀██▀▀▀██
██░▀░██░█░███░▀██░███▄█
█▄███▄██▄████▄████▄▄▄██
██▀ ▀███▀▀░▀██▀▀▀██████
███▄███░▄▀██████▀█▀█▀▀█
████▀▀██▄▀█████▄█▀███▄█
███▄▄▄████████▄█▄▀█████
███▀▀▀████████████▄▀███
███▄░▄█▀▀▀██████▀▀▀▄███
███████▄██▄▌████▀▀█████
▀██▄█████▄█▄▄▄██▄████▀
▀▀██████████▄▄███▀▀
▀▀▀▀█▀▀▀▀
.
EUROPEAN
BETTING
PARTNER
Upgrade00
Legendary
*
Offline Offline

Activity: 2030
Merit: 2174


Professional Community manager


View Profile WWW
February 28, 2023, 07:52:04 PM
 #5

What now remains to be seen is what the actual origin of the data for the phishing campaign is, and whether it is random (but based on a crypto related user list) or specific to Trezor.
My exact reservations. I don't expect that a random scam attempt would be given such attention as this was and for such a scam to be actually effective, it would have to target actual users of Trezor. I could of course be wrong.

As you pointed out, it could be a previous breach or a more recent one.

.BEST..CHANGE.███████████████
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
███████████████
..BUY/ SELL CRYPTO..
BitMaxz
Legendary
*
Offline Offline

Activity: 3248
Merit: 2972


Block halving is coming.


View Profile WWW
February 28, 2023, 11:48:38 PM
 #6

It's obviously a phishing attempt look why would Trezor send an SMS? When generating a wallet with Trezor it doesn't require adding a phone number so it's weird that you will receive an SMS from Trezor support. Only Newbies/Dumb can mostly victims of such a scheme.

I never receive an Sms like that or any phishing attempt through Text but I mostly receive SMS from Casino. So it's weird that Trezor will send you like that and another thing you will notice is the domain link they provide which is far from the trezor website

█▀▀▀











█▄▄▄
▀▀▀▀▀▀▀▀▀▀▀
e
▄▄▄▄▄▄▄▄▄▄▄
█████████████
████████████▄███
██▐███████▄█████▀
█████████▄████▀
███▐████▄███▀
████▐██████▀
█████▀█████
███████████▄
████████████▄
██▄█████▀█████▄
▄█████████▀█████▀
███████████▀██▀
████▀█████████
▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀
c.h.
▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄
▀▀▀█











▄▄▄█
▄██████▄▄▄
█████████████▄▄
███████████████
███████████████
███████████████
███████████████
███░░█████████
███▌▐█████████
█████████████
███████████▀
██████████▀
████████▀
▀██▀▀
Sarah Azhari
Hero Member
*****
Offline Offline

Activity: 868
Merit: 739


View Profile
March 01, 2023, 01:04:32 AM
 #7

If you are a Trezor user, did you receive any emails, SMS, or calls from scammers? 
Just confused about, how the scammer finds our phone number to send SMS and calls. I just received a call several days ago with I don't understand the language from a strange phone number, but I am really sure that he make the offer for me, and I don't interesting to continue his call. So how can I block phone number from outside country?
Rikafip
Legendary
*
Offline Offline

Activity: 1750
Merit: 5990



View Profile WWW
March 01, 2023, 07:33:36 AM
Merited by Pmalek (2)
 #8

Just confused about, how the scammer finds our phone number to send SMS and calls. I just received a call several days ago with I don't understand the language from a strange phone number, but I am really sure that he make the offer for me, and I don't interesting to continue his call.
This leak doesn't have to be from Trezor, as you might have left your phone number somewhere else and they could have leaked it. It can be an exchange or maybe even from that Ledger leak from few years ago. For that reason its a good idea to get virtual phone number (that costs like few dollars) if you want to register on dodgy websites that ask for your phone number.


So how can I block phone number from outside country?
Same as any other phone number, as you have option for that inside your phone call settings.

██
██
██
██
██
██
██
██
██
██
██
██
██
... LIVECASINO.io    Play Live Games with up to 20% cashback!...██
██
██
██
██
██
██
██
██
██
██
██
██
Lucius
Legendary
*
Offline Offline

Activity: 3234
Merit: 5676


Blackjack.fun🎲


View Profile WWW
March 01, 2023, 11:44:19 AM
 #9

I am not a Trezor user and I can say that so far I have not received any SMS or call, and we can only guess where the scammer got the database from. Maybe it's the Ledger database, maybe someone else, and maybe someone hacked the Trezor database, but they're not even aware of it, or they're still pretending it didn't happen.



~snip~
- Don't fall for it because it's fake!
- If you are a Trezor user, don't click on unknown links and answer calls from unknown numbers.
It's the oldest trick in the book.

E-mail is the least dangerous here because most of such messages end up in the spam folder anyway, while SMS and calls are something that is far more unsettling to users and can trick them into taking some reckless action. It is easiest to block calls from unknown numbers or even SMS messages in the same way, but not all such calls or messages are malicious.

.
.BLACKJACK ♠ FUN.
█████████
██████████████
████████████
█████████████████
████████████████▄▄
░█████████████▀░▀▀
██████████████████
░██████████████
████████████████
░██████████████
████████████
███████████████░██
██████████
CRYPTO CASINO &
SPORTS BETTING
▄▄███████▄▄
▄███████████████▄
███████████████████
█████████████████████
███████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
███████████████████████
█████████████████████
███████████████████
▀███████████████▀
█████████
.
Coyster
Legendary
*
Offline Offline

Activity: 2016
Merit: 1248


Cashback 15%


View Profile
March 01, 2023, 12:14:50 PM
 #10

Tbh i know that quite a lot of people can fall victim to this kind of scam, that is why anytime i see something like this i don't see the victims as complete dumbasses, because i know how poor (extremely poor) my personal security was before i became a user on Bitcointalk. That's why the first thing i do once i have a friend who uses crypto is to introduce them to this forum, i think it is going to be extremely difficult for a long time user in this forum to fall for something like this.

This kind of scam is quite popular in my country, but their modus operandi is quite different because they use the traditional banking system as bait: you receive a strange call and the person claims to be a worker in your bank telling you that there's some problem with your account that needs to be solved, the scammer goes ahead to request for the sensitive numbers on your ATM card coupled with other details...whenever i get a call like this i usually toy with the scammer by allowing them waste all their time talking, and when he believes he has gotten to me...i end the call with a resounding "fuck you". Grin Grin

.
.HUGE.
▄██████████▄▄
▄█████████████████▄
▄█████████████████████▄
▄███████████████████████▄
▄█████████████████████████▄
███████▌██▌▐██▐██▐████▄███
████▐██▐████▌██▌██▌██▌██
█████▀███▀███▀▐██▐██▐█████

▀█████████████████████████▀

▀███████████████████████▀

▀█████████████████████▀

▀█████████████████▀

▀██████████▀▀
█▀▀▀▀











█▄▄▄▄
▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀
.
CASINSPORTSBOOK
▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄
▀▀▀▀█











▄▄▄▄█
DdmrDdmr
Legendary
*
Offline Offline

Activity: 2310
Merit: 10759


There are lies, damned lies and statistics. MTwain


View Profile WWW
March 01, 2023, 05:36:45 PM
Merited by Pmalek (2), SFR10 (1)
 #11

The site shown in the OP seems to have been taken down by Namecheap, alongside some other different domain names they’ve been using in this campaign, diversifying domain names being used, I figure, in order to try to stay in the game longer.

See: https://twitter.com/dubstard/status/1630634978110259214

Trezor tweeted that the campaign is allegedly atacking people randomly (see also this and this other tweet), based on what seems to be reports made by people receiving the messages whilst not being Trezor customers. Of course the randomness has a basis of at least probably targeting crypto related people, with data obtained from leaks compiled into databases that are out and about.
Little Mouse
Legendary
*
Offline Offline

Activity: 2044
Merit: 1981


Marketing Campaign Manager |Telegram ID- @LT_Mouse


View Profile WWW
March 01, 2023, 05:59:31 PM
 #12

SMS, email, and even phone.
That's quite strange! Did Trezor have a data breach, I can't remember? Otherwise, how come they get the phone number? Or hacker is calling some random guy from another crypto-related database?

while SMS and calls are something that is far more unsettling to users and can trick them into taking some reckless action.

SMS is a great way of having someone to click if a message can be sent in the name of an official. I have been tricked by this method and lost $300.
Trezor tweeted that the campaign is allegedly atacking people randomly (see also this and this other tweet), based on what seems to be reports made by people receiving the messages whilst not being Trezor customers. Of course the randomness has a basis of at least probably targeting crypto related people, with data obtained from leaks compiled into databases that are out and about.

My bad, I didn't notice this. That means the hacker is targeting random users in terms of trezor customers but it seems they have stolen any other crypto database. Ridiculous how things going on here.

██████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
██████████████████████
.SHUFFLE.COM..███████████████████████
███████████████████████
███████████████████████
███████████████████████
███████████████████████
█████████████████████
████████████████████
██████████████████████
████████████████████
██████████████████████
███████████████████████
███████████████████████
███████████████████████
███████████████████████
███████████████████████
███████████████████████
██████████████████████
██████████████████████
██████████████████████
███████████████████████
███████████████████████
███████████████████████
███████████████████████
███████████████████████
███████████████████████
███████████████████████
.
...Next Generation Crypto Casino...
Pmalek (OP)
Legendary
*
Offline Offline

Activity: 2758
Merit: 7138



View Profile
March 01, 2023, 06:41:16 PM
 #13

It's obviously a phishing attempt look why would Trezor send an SMS? When generating a wallet with Trezor it doesn't require adding a phone number so it's weird that you will receive an SMS from Trezor support. Only Newbies/Dumb can mostly victims of such a scheme.
People who fall victims to obvious phishing scams like this don't really apply that sort of logic. Otherwise, the things you said would be clear to them as well. Although, you do provide Trezor with a phone number when you order their products. But still, don't expect them to SMS or call every single customer.

.
.BLACKJACK ♠ FUN.
█████████
██████████████
████████████
█████████████████
████████████████▄▄
░█████████████▀░▀▀
██████████████████
░██████████████
████████████████
░██████████████
████████████
███████████████░██
██████████
CRYPTO CASINO &
SPORTS BETTING
▄▄███████▄▄
▄███████████████▄
███████████████████
█████████████████████
███████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
███████████████████████
█████████████████████
███████████████████
▀███████████████▀
█████████
.
Dave1
Hero Member
*****
Offline Offline

Activity: 1302
Merit: 522



View Profile
March 02, 2023, 01:47:24 AM
 #14

Yes, this is the one of the oldest trick in the book. Funny thing is that even if I don't own a Trezor right now, but for sure even those who don't know are getting this kind of text message so it's an obvious scam.

And as per Trezor itself:

-We will never contact you via calls or SMS.

R


▀▀▀▀▀▀▀██████▄▄
████████████████
▀▀▀▀█████▀▀▀█████
████████▌███▐████
▄▄▄▄█████▄▄▄█████
████████████████
▄▄▄▄▄▄▄██████▀▀
LLBIT
  CRYPTO   
FUTURES
 1,000x 
LEVERAGE
COMPETITIVE
    FEES    
 INSTANT 
EXECUTION
.
   TRADE NOW   
Pages: [1]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!