Bitcoin Forum
September 22, 2026, 05:43:35 PM *
News: Latest Bitcoin Core release: 31.1 [Torrent]
 
   Home   Help Search Login Register More  
Pages: [1] 2 »  All
  Print  
Author Topic: Becareful if you are using a keystone hardware wallet  (Read 279 times)
5W-KILO (OP)
Full Member
***
Online Online

Activity: 379
Merit: 176



View Profile
September 12, 2026, 04:40:03 PM
 #1

I got mail from keystone and I had to contact keystone team to make sure that my curiosity was right.
The move this time around doesn't look like a scam, they wanted you to click link to check things out.

This people are getting smarter.
Data leak I guess, because how did the know the exact email address that I used to purchase the hardware wallet?



The keystone team clarified that it's a scam attempt but they never said anything about how the scams are directed byo people who really bought a hardware wallet, is this going to keep going like this?



This attack isn't about asking anyone to drop their recovery seed, it's about you making a move on the links in the mail, this is why it's always good to verify first before acting, and this whole drama even sound funny, it doesn't look genuine but not to beginners.

Remain guided.

Nwada001
Hero Member
*****
Offline

Activity: 1442
Merit: 888



View Profile
September 12, 2026, 04:52:24 PM
Merited by Pmalek (3), ABCbits (1)
 #2

KYC verification for hardware wallet? These scammers don’t even know what to come up with as part of the new updated policy. Is a hardware wallet an exchange, which they will talk about the anti-money laundering policy?

Thanks for the warning. Even without contacting the team of Keystone, someone who is familiar with this scammers should be able to detect their pattern. If you also check the domain of the mail, it might also leave some holes to identify that it’s not from the official team.

You should also add this warning to this thread:  crypto scam attacks/attempts

 
█▄
R


▀▀██████▄▄
████████████████
▀█████▀▀▀█████
████████▌███▐████
▄█████▄▄▄█████
████████████████
▄▄██████▀▀
LLBIT▀█ 
  TH#1 SOLANA CASINO  
████████████▄
▀▀██████▀▀███
██▄▄▀▀▄▄████
████████████
██████████
███▀████████
▄▄█████████
████████████
████████████
████████████
████████████
█████████████
████████████▀
████████████▄
▀▀▀▀▀▀▀██████
████████████
███████████
██▄█████████
████▄███████
████████████
█░▀▀████████
▀▀██████████
█████▄█████
████▀▄▀████
▄▄▄▄▄▄▄██████
████████████▀
........5,000+........
GAMES
 
......INSTANT......
WITHDRAWALS
..........HUGE..........
REWARDS
 
............VIP............
PROGRAM
 .
   PLAY NOW    
[/quote]
Code:
[center][table][tr][td][/td][td][size=20pt][nbsp]
[size=6pt][color=#65e]█▄[/td]
[td][font=arial black][size=24pt]R[/size][/font][/td]
[td][size=2pt]


[color=#fec]▀[color=#fda]▀[color=#fc9]▀[color=#eb7]▀[color=#eb5]▀[col
Filicius
Sr. Member
****
Online Online

Activity: 756
Merit: 416


ENG>SPA translator


View Profile
September 12, 2026, 05:09:29 PM
Merited by The Sceptical Chymist (3)
 #3

When I read the title I thought that it could be another mistake in Coldcard's style, but it seems more like another case of personal data leakage, as we are unfortunately used to even by leading companies in the sector. Although it may seem to us that the scam in this case is crude and no one would fall for it, as Nwada001 said, the truth is that it is enough for a minimum percentage of users to fall into the trap for the scheme to be profitable.

I personally do not own any keystone hardware wallet, but this new case reinforces the idea that you have to doubt any unsolicited communication, always, systematically, and without exception. And of course, always ask yourself seriously if you should really carry out a KYC anywhere, and never ever in life share your keys or seed phrases.

Finally, a time limit, such as the 10 days mentioned, is a full-blown red flag. Scammers are always going to try to create a sense of urgency in you so that you stress out and don't think twice.


 BetBolt.com  
███████████████████████
███████████████████████
███████████████████████
██████████████████████
█████████████████████
██████████████████████
██████████████████████
███████████████████
██████████████████████
███████████████████████
███████████████████████
███████████████████████
▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀
🗲
███    ███████████████████████████████████████

CRYPTO'S MOST REWARDING CASINO

███████████████████████████████████████    ███
██████▄██████▄▄
███▄██████████████▄▄
▄███████████████████
█████████████████████
▀███████
████████████████▄
█████████████████████████
███▀███████████████████▀
█████████████████████▀▀
██████▀███████████▀▀
███████████████▀▀
█████████▀█▀▀
    PLAY NOW   



███▄▄▄▄███
████████████
███████████▀
████████▄
█████████▄
█████▀█████▄
▀██████▀█████
██████████▀██▀
Lucius
Legendary
*
Offline

Activity: 4102
Merit: 7811


A swap that needs a hand? zeto.cash@proton.me


View Profile WWW
September 13, 2026, 01:03:52 PM
 #4

I got mail from keystone and I had to contact keystone team to make sure that my curiosity was right.
The move this time around doesn't look like a scam, they wanted you to click link to check things out.
This people are getting smarter.
Data leak I guess, because how did the know the exact email address that I used to purchase the hardware wallet?
~snip~


Have you perhaps used that email for anything else related to cryptocurrency? It is possible that they suffered a database leak, as that has been happening a lot lately, but it is also possible that scammers are sending such emails at random.

Back when I didn't have a Trezor, I frequently received phishing emails specifically linked to that hardware wallet, and the reason was evidently a different hacked database. My advice to everyone is not to trust any e-mail that has anything to do with hardware wallets and cryptocurrencies - always look for information on the manufacturer's official website.

DaveF
Legendary
*
Offline

Activity: 4340
Merit: 7547


✅ NO KYC


View Profile WWW
September 13, 2026, 01:10:59 PM
Merited by The Sceptical Chymist (4), ABCbits (1)
 #5

Or, it's just the shotgun approach. Send this to every email address they have from every leak everyplace.

I have gotten emails about crypto stuff to email accounts that have never seen or done anything related to crypto.
Some were even 1 use disposable addresses.

Sadly it's just the world we live in.

-Dave

▄▄████████████████████▄▄
▄███████▀▀██████▀▀███████▄
████████████████████████
████████▄▄██████▄▄██████

████████████████████████
██▄▄█████████████▄▄██████
██▀▀██████████████████▄▄██
██████▀▀██████████████▀▀██
██████████████████████████
██████▀▀██████▀▀████████
████████████████████████
▀███████▄▄██████▄▄███████▀
▀▀████████████████████▀▀
 
 DΞX.fo 
▄▄██████
█████████
██████████
█████████
██████████
█████████
▀▀██████

▄███████
▄██████████
████████████
█████████████
█████████████
|
▄▄█
▄████▀
▄███▀
▄██▀▄██
█████▀▀
███████
████████
▀██▄████
▄████▄▄
▄█████▀███
▄█████▀████
█████▀███████
▀██▀█████████
|..BTC......XMR...
..USDT.....LTC...
....Fees  0.8%.....
Pmalek
Legendary
*
Offline

Activity: 3626
Merit: 9560



View Profile
September 13, 2026, 03:36:18 PM
 #6

Some thoughts after looking at the images. They are talking about restricting certain actions like account withdrawals. What accounts and what withdrawals? You have a non-custodial wallet, not an account. No one can restrict you from sending or accepting cryptocurrencies to addresses you generated with it. It's not a custodial account at an exchange. There is no KYC with non-custodial wallets because you don't need to ask anyone for permission to do with your money and your keys what you want. They keep mentioning "withdrawals" throughout the email. That's a big giveaway that something is wrong even if the email is professionally written. We don't say that you deposit or withdraw to/from Keystone/Trezor/Seedsigner, etc.

Have you checked what happens and what opens if you click on "Policy Review Agreement" or "Hardware Wallet Agreement?" Maybe that's where they want potential victims to enter their seeds.
Your email address they sent this to was part of a leak somewhere. That's how they got it. Something was leaked. Is it an email address that has received similar spam and scam attempts before?

▄▄███████████████████▄▄
▄███████████████████████▄
████████████████████████
█████████████████████████
████████████████████████
████████████▀██████▀████
████████████████████████
█████████▄▄▄▄███████████
██████████▄▄▄████████████
████████████████████████
████████████████▀▀███████
▀███████████████████████▀
▀▀███████████████████▀▀
 
 EARNBET 
| 🏀
 
🏈 🏓
 
🎯 🥊
 
 🎾
 
 🏐
 
🏏 🏎️
|


███████▄▄███████████
████▄██████████████████
██▀▀███████████████▀▀███
▄████████████████████████
▄▄████████▀▀▀▀▀████████▄▄██
███████████████████████████
█████████▌██▀████████████
███████████████████████████
▀▀███████▄▄▄▄▄█████████▀▀██
▀█████████████████████▀██
██▄▄███████████████▄▄███
████▀██████████████████
███████▀▀███████████

....HIGHEST....
VIP REWARDS

  G U A R A N T E E D   
| 
 🜲 
KING OF
THE CASTLE

$200K in prizes
| 
..PLAY NOW..
5W-KILO (OP)
Full Member
***
Online Online

Activity: 379
Merit: 176



View Profile
September 13, 2026, 06:32:44 PM
 #7

Some thoughts after looking at the images. They are talking about restricting certain actions like account withdrawals. What accounts and what withdrawals? You have a non-custodial wallet, not an account. No one can restrict you from sending or accepting cryptocurrencies to addresses you generated with it. It's not a custodial account at an exchange. There is no KYC with non-custodial wallets because you don't need to ask anyone for permission to do with your money and your keys what you want. They keep mentioning "withdrawals" throughout the email. That's a big giveaway that something is wrong even if the email is professionally written. We don't say that you deposit or withdraw to/from Keystone/Trezor/Seedsigner, etc.

Have you checked what happens and what opens if you click on "Policy Review Agreement" or "Hardware Wallet Agreement?" Maybe that's where they want potential victims to enter their seeds.
Your email address they sent this to was part of a leak somewhere. That's how they got it. Something was leaked. Is it an email address that has received similar spam and scam attempts before?

Hi Pmalek, I'm not ready to click that link for testing purposes 😅

It can never be me, because if checking out the link is what they want you to do it's over, maybe the goal isn't to ask for recovery seed but to inject somekind of Trojan or Malware onto my PC, Maybe all they need is one click only.

Come to think about this, it sound stupid, like people will really want to know what isn't waiting on the next click, and I feel like that's their goal, just one click and it's over.

If you want to try I can forward to your email address, shall we?

m2017
Legendary
*
Offline

Activity: 2618
Merit: 1732


keep walking, Johnnie


View Profile
September 14, 2026, 06:10:17 AM
 #8

KYC verification for hardware wallet? These scammers don’t even know what to come up with as part of the new updated policy.
You might be laughing now, but just wait: governments will overregulate the market for hardware wallets, and even here, they’ll force you to undergo KYC verification (all for the greater good and to fight against everything bad).

Right now, such emails come from scammers, but the time will come when similar messages arrive from the device manufacturers themselves, acting under pressure from regulators (if not in every country, then at least in some).

Is a hardware wallet an exchange, which they will talk about the anti-money laundering policy?
It isn’t an exchange, but funds flow through these HW devices, and the regulator will certainly want to know "where it came from and where it went".

Thanks for the warning. Even without contacting the team of Keystone, someone who is familiar with this scammers should be able to detect their pattern.
And what about those who fail to spot the telltale signs - will they become victims? Scammers target such people rather than "savvy experts", banking on the fact that a certain percentage of all email recipients will fall into the trap.

If you also check the domain of the mail, it might also leave some holes to identify that it’s not from the official team.
Few people will start verifying the details once they see that these changes are a regulatory requirement (manipulation through submission to authority).

Pmalek
Legendary
*
Offline

Activity: 3626
Merit: 9560



View Profile
September 14, 2026, 06:54:47 AM
 #9

Hi Pmalek, I'm not ready to click that link for testing purposes 😅

It can never be me, because if checking out the link is what they want you to do it's over, maybe the goal isn't to ask for recovery seed but to inject somekind of Trojan or Malware onto my PC, Maybe all they need is one click only.

Come to think about this, it sound stupid, like people will really want to know what isn't waiting on the next click, and I feel like that's their goal, just one click and it's over.

If you want to try I can forward to your email address, shall we?
I thought you already clicked on the links, but nevermind. I wouldn't do it either, so I understand the skepticism. You seem to be using a phone. If you have computer, you can hover over it with your mouse and check the bottom left corner of your screen if it shows the website it leads to. Alternatively, a right-click on it with your mouse and then clicking on "Copy link address" will copy the address. You can then paste it into a browser to inspect where it goes without actually going to the website. Or you can paste it into a text document, etc. They might be hiding the true destination behind redirection links and you can reveal it with the help of redirect checkers.

It can be malware, you are right. Usually it isn't. Scammers tend to rely on social engineering schemes because they work.

You might be laughing now, but just wait: governments will overregulate the market for hardware wallets, and even here, they’ll force you to undergo KYC verification (all for the greater good and to fight against everything bad).
Don't forget that it's for the safety of our children. You don't hate the children, do you? Roll Eyes

▄▄███████████████████▄▄
▄███████████████████████▄
████████████████████████
█████████████████████████
████████████████████████
████████████▀██████▀████
████████████████████████
█████████▄▄▄▄███████████
██████████▄▄▄████████████
████████████████████████
████████████████▀▀███████
▀███████████████████████▀
▀▀███████████████████▀▀
 
 EARNBET 
| 🏀
 
🏈 🏓
 
🎯 🥊
 
 🎾
 
 🏐
 
🏏 🏎️
|


███████▄▄███████████
████▄██████████████████
██▀▀███████████████▀▀███
▄████████████████████████
▄▄████████▀▀▀▀▀████████▄▄██
███████████████████████████
█████████▌██▀████████████
███████████████████████████
▀▀███████▄▄▄▄▄█████████▀▀██
▀█████████████████████▀██
██▄▄███████████████▄▄███
████▀██████████████████
███████▀▀███████████

....HIGHEST....
VIP REWARDS

  G U A R A N T E E D   
| 
 🜲 
KING OF
THE CASTLE

$200K in prizes
| 
..PLAY NOW..
5W-KILO (OP)
Full Member
***
Online Online

Activity: 379
Merit: 176



View Profile
September 14, 2026, 06:32:39 PM
Last edit: September 15, 2026, 05:02:40 AM by 5W-KILO
Merited by Pmalek (3)
 #10

Hi Pmalek, I'm not ready to click that link for testing purposes 😅

It can never be me, because if checking out the link is what they want you to do it's over, maybe the goal isn't to ask for recovery seed but to inject somekind of Trojan or Malware onto my PC, Maybe all they need is one click only.

Come to think about this, it sound stupid, like people will really want to know what isn't waiting on the next click, and I feel like that's their goal, just one click and it's over.

If you want to try I can forward to your email address, shall we?
I thought you already clicked on the links, but nevermind. I wouldn't do it either, so I understand the skepticism. You seem to be using a phone. If you have computer, you can hover over it with your mouse and check the bottom left corner of your screen if it shows the website it leads to. Alternatively, a right-click on it with your mouse and then clicking on "Copy link address" will copy the address. You can then paste it into a browser to inspect where it goes without actually going to the website. Or you can paste it into a text document, etc. They might be hiding the true destination behind redirection links and you can reveal it with the help of redirect checkers.

It can be malware, you are right. Usually it isn't. Scammers tend to rely on social engineering schemes because they work.

You might be laughing now, but just wait: governments will overregulate the market for hardware wallets, and even here, they’ll force you to undergo KYC verification (all for the greater good and to fight against everything bad).
Don't forget that it's for the safety of our children. You don't hate the children, do you? Roll Eyes


I decided to do more research on this scam and it seems like they are trying to push an instant update firmware 2.4

And as a matter of reality there is no version of that firmware update on real keystone website.
The latest firmware update on Keystone official website is 3.0+

Here is the link from the scam email

https://www.keystone-policyreview.live/

I used a mobile phone to visit the link, because I can't risk my PC, even to view like you direct is a no, I believe they will likely push Trojan or bad update.



See that Accept and Continue click behaves abnormal, I still believe that it's going to run something in the background if run or click on PC, and that's something I wouldn't do but anyways, here is where I rest my case, since the keystone team claimed its scam attempt I am fine.

They did a great job on the website, almost confusing, each details are almost perfectly merged together.

UPDATE

A download was pushed to my phone, i don't even know that my chrome browser was downloading anything in the background until some hours later.


I think this is it, a program or Trojan that you must run on PC and in .Bat file?

Pmalek
Legendary
*
Offline

Activity: 3626
Merit: 9560



View Profile
September 15, 2026, 06:35:08 AM
 #11

UPDATE

A download was pushed to my phone, i don't even know that my chrome browser was downloading anything in the background until some hours later.


I think this is it, a program or Trojan that you must run on PC and in .Bat file?
That's a batch file. Those work on Windows but not on Android. Essentially, it's a script file that can execute commands by the person that created it. It can turn things off, turn things on, and yes it can instruct a computer to download something else from a different website. Even if you are on Android, you should absolutely not run it. I don't know what would happen and if Android recognizes .bat files. It probably doesn't.

The last thing you can do if you still have the file is to scan it on VirusTotal: https://www.virustotal.com/gui/home/upload
It will scan the file with various AVs and display results. If it's malware infected, you will see multiple AV brands tag it as such. Even if it isn't, that doesn't make it safe.

▄▄███████████████████▄▄
▄███████████████████████▄
████████████████████████
█████████████████████████
████████████████████████
████████████▀██████▀████
████████████████████████
█████████▄▄▄▄███████████
██████████▄▄▄████████████
████████████████████████
████████████████▀▀███████
▀███████████████████████▀
▀▀███████████████████▀▀
 
 EARNBET 
| 🏀
 
🏈 🏓
 
🎯 🥊
 
 🎾
 
 🏐
 
🏏 🏎️
|


███████▄▄███████████
████▄██████████████████
██▀▀███████████████▀▀███
▄████████████████████████
▄▄████████▀▀▀▀▀████████▄▄██
███████████████████████████
█████████▌██▀████████████
███████████████████████████
▀▀███████▄▄▄▄▄█████████▀▀██
▀█████████████████████▀██
██▄▄███████████████▄▄███
████▀██████████████████
███████▀▀███████████

....HIGHEST....
VIP REWARDS

  G U A R A N T E E D   
| 
 🜲 
KING OF
THE CASTLE

$200K in prizes
| 
..PLAY NOW..
5W-KILO (OP)
Full Member
***
Online Online

Activity: 379
Merit: 176



View Profile
September 15, 2026, 12:17:44 PM
 #12

UPDATE

A download was pushed to my phone, i don't even know that my chrome browser was downloading anything in the background until some hours later.


I think this is it, a program or Trojan that you must run on PC and in .Bat file?
That's a batch file. Those work on Windows but not on Android. Essentially, it's a script file that can execute commands by the person that created it. It can turn things off, turn things on, and yes it can instruct a computer to download something else from a different website. Even if you are on Android, you should absolutely not run it. I don't know what would happen and if Android recognizes .bat files. It probably doesn't.

The last thing you can do if you still have the file is to scan it on VirusTotal: https://www.virustotal.com/gui/home/upload
It will scan the file with various AVs and display results. If it's malware infected, you will see multiple AV brands tag it as such. Even if it isn't, that doesn't make it safe.

I've been an android freak since Android 2.1, I've never for once seen where bat file runs on Android, but you can view what's inside the .bat file using WPS app others that can view .bat in document style.

Here is what's inside this one



This nonsense in the bat file is never ending, too long to take screenshot of everything, this will only work or execute on a windows PC, you run this on PC it can be too late already, I don't even want to risk moving it to my PC.

maydna
Hero Member
*****
Offline

Activity: 3794
Merit: 587


View Profile
September 15, 2026, 01:26:01 PM
 #13

Glad to see you are not panic and verify the email by contacting keystone team and found that is scams. The scammers are getting smarter and no doubts about that but the victims are not just you, I am afraid. Among other victims, some people may panic and just follow the instruction on the email without thinks that is scams or not.

Verification is the key here to avoids scam so we know that is real or fake. The scammers itself will search for other ways to trick their victims but if we can verify like you did, I am sure people will stay away from scammers.

We must not panic so we can think clear about the situation and contact the developer in the official site so that helps us to stay away from scammers.
The Sceptical Chymist
Legendary
*
Offline

Activity: 4200
Merit: 7383


♻️ Automatic Exchange


View Profile
September 15, 2026, 03:49:36 PM
 #14

I have gotten emails about crypto stuff to email accounts that have never seen or done anything related to crypto.

Same here, and I think you're right about these idiot scammers using what you described as a shotgun approach (which in this case is probably equivalent to the law of large numbers).  I've never owned a Trezor and yet I've gotten e-mails about some kind of BS going on with their devices as if they were coming from the manufacturer, and  I've also gotten e-mails regarding other HW wallets, too.  Makes me think that if you give your e-mail address out to any kind of service in the wonderful, wide world of cryptocurrency, you can consider it to be on a bunch of scammers' lists--probably being traded on the dark web like people's credit cards or full dox.

It's probably good cyber hygiene to use throwaway e-mail addresses when possible, although I would hope that's advice privacy-loving peeps practice as a matter of course.  If not, learn the easy way from those of us who learned the hard way.

░░░░▄▄████████████▄
▄████████████████▀
▄████████████████▀▄█▄
▄██████▀▀░░▄███▀▄████▄
▄██████▀░░░▄███▀▀██████▄
██████▀░░▄████▄░░░▀██████
██████░░▀▀▀▀▄▄▄▄░░██████
██████▄░░░▀████▀░░▄██████
▀██████▄▄███▀░░░▄██████▀
▀████▀▄████░░▄▄███████▀
▀█▀▄████████████████▀
▄████████████████▀
▀████████████▀▀░░░░
 
 CCECASH 
 
    ANN THREAD    
 
      TUTORIAL      
Pmalek
Legendary
*
Offline

Activity: 3626
Merit: 9560



View Profile
September 15, 2026, 03:56:56 PM
 #15

@5W-KILO
Perhaps Keystone was in some way associated and partnered with Brevo in the past. It's the third-party email service provider that Trezor and Bitbox cooperated with as well and whose data leaked recently. It wouldn't be that surprising. Maybe Keystone is not yet aware of how many of their users are impacted and are still waiting to make an announcement until they have more information to share.

▄▄███████████████████▄▄
▄███████████████████████▄
████████████████████████
█████████████████████████
████████████████████████
████████████▀██████▀████
████████████████████████
█████████▄▄▄▄███████████
██████████▄▄▄████████████
████████████████████████
████████████████▀▀███████
▀███████████████████████▀
▀▀███████████████████▀▀
 
 EARNBET 
| 🏀
 
🏈 🏓
 
🎯 🥊
 
 🎾
 
 🏐
 
🏏 🏎️
|


███████▄▄███████████
████▄██████████████████
██▀▀███████████████▀▀███
▄████████████████████████
▄▄████████▀▀▀▀▀████████▄▄██
███████████████████████████
█████████▌██▀████████████
███████████████████████████
▀▀███████▄▄▄▄▄█████████▀▀██
▀█████████████████████▀██
██▄▄███████████████▄▄███
████▀██████████████████
███████▀▀███████████

....HIGHEST....
VIP REWARDS

  G U A R A N T E E D   
| 
 🜲 
KING OF
THE CASTLE

$200K in prizes
| 
..PLAY NOW..
X-ray
Hero Member
*****
Offline

Activity: 3738
Merit: 576


Leading Crypto Sports Betting & Casino Platform


View Profile
September 17, 2026, 02:26:31 AM
Last edit: September 17, 2026, 03:22:21 AM by X-ray
 #16

I've been an android freak since Android 2.1, I've never for once seen where bat file runs on Android, but you can view what's inside the .bat file using WPS app others that can view .bat in document style.

Here is what's inside this one



This nonsense in the bat file is never ending, too long to take screenshot of everything, this will only work or execute on a windows PC, you run this on PC it can be too late already, I don't even want to risk moving it to my PC.
These are bunch of obfuscated code inside a bat file, they are targeting specifically windows user indeed, could be an info stealer type of malware that looks for seed phrases in your windows PC.

As we can see the script is executing .exe file, it won't run on any other OSes but windows.

Again, another reminder that saving seed phrase in our windows PC is not safe and simple info stealer could steal our money easily.

On the other hand, I wish these companies would look at their user data leak report seriously, concealing the matter is only going to hurt their reputation and hurt their customers.

Companies that aren't honest relating to safety of their customer's asset are utterly evil, frankly speaking.

..Stake.com..   ▄████████████████████████████████████▄
   ██ ▄▄▄▄▄▄▄▄▄▄            ▄▄▄▄▄▄▄▄▄▄ ██  ▄████▄
   ██ ▀▀▀▀▀▀▀▀▀▀ ██████████ ▀▀▀▀▀▀▀▀▀▀ ██  ██████
   ██ ██████████ ██      ██ ██████████ ██   ▀██▀
   ██ ██      ██ ██████  ██ ██      ██ ██    ██
   ██ ██████  ██ █████  ███ ██████  ██ ████▄ ██
   ██ █████  ███ ████  ████ █████  ███ ████████
   ██ ████  ████ ██████████ ████  ████ ████▀
   ██ ██████████ ▄▄▄▄▄▄▄▄▄▄ ██████████ ██
   ██            ▀▀▀▀▀▀▀▀▀▀            ██ 
   ▀█████████▀ ▄████████████▄ ▀█████████▀
  ▄▄▄▄▄▄▄▄▄▄▄▄███  ██  ██  ███▄▄▄▄▄▄▄▄▄▄▄▄
 ██████████████████████████████████████████
▄▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▄
█  ▄▀▄             █▀▀█▀▄▄
█  █▀█             █  ▐  ▐▌
█       ▄██▄       █  ▌  █
█     ▄██████▄     █  ▌ ▐▌
█    ██████████    █ ▐  █
█   ▐██████████▌   █ ▐ ▐▌
█    ▀▀██████▀▀    █ ▌ █
█     ▄▄▄██▄▄▄     █ ▌▐▌
█                  █▐ █
█                  █▐▐▌
█                  █▐█
▀▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▀█
▄▄█████████▄▄
▄██▀▀▀▀█████▀▀▀▀██▄
▄█▀       ▐█▌       ▀█▄
██         ▐█▌         ██
████▄     ▄█████▄     ▄████
████████▄███████████▄████████
███▀    █████████████    ▀███
██       ███████████       ██
▀█▄       █████████       ▄█▀
▀█▄    ▄██▀▀▀▀▀▀▀██▄  ▄▄▄█▀
▀███████         ███████▀
▀█████▄       ▄█████▀
▀▀▀███▄▄▄███▀▀▀
..PLAY NOW..
5W-KILO (OP)
Full Member
***
Online Online

Activity: 379
Merit: 176



View Profile
September 17, 2026, 04:30:45 PM
 #17

I've been an android freak since Android 2.1, I've never for once seen where bat file runs on Android, but you can view what's inside the .bat file using WPS app others that can view .bat in document style.

Here is what's inside this one



This nonsense in the bat file is never ending, too long to take screenshot of everything, this will only work or execute on a windows PC, you run this on PC it can be too late already, I don't even want to risk moving it to my PC.
These are bunch of obfuscated code inside a bat file, they are targeting specifically windows user indeed, could be an info stealer type of malware that looks for seed phrases in your windows PC.

As we can see the script is executing .exe file, it won't run on any other OSes but windows.

Again, another reminder that saving seed phrase in our windows PC is not safe and simple info stealer could steal our money easily.

On the other hand, I wish these companies would look at their user data leak report seriously, concealing the matter is only going to hurt their reputation and hurt their customers.

Companies that aren't honest relating to safety of their customer's asset are utterly evil, frankly speaking.

Exactly, this is why I edited the file on a android phone, I can't risk moving the file onto my computer, it's already showing in the .Bat file that this file will run a script on the PC and it will take over everything, files especially and also sensitive words that looks like recovery seed.

Computers are more dangerous for crypto wallets than hardware wallet itself, before anyone says that ColdCard just proven hardware wallets wrong we can't compare running a wallet on a computer to keeping your coins on a cold storage.

Keystone messed up a bit here, they don't inform or talked about this attackers attempt, I pushed it all out but they said nothing about it, also why are hardware wallet producers holding information of their buyers? After successful sells why not wipe them off instead?

X-ray
Hero Member
*****
Offline

Activity: 3738
Merit: 576


Leading Crypto Sports Betting & Casino Platform


View Profile
September 18, 2026, 03:58:20 AM
 #18

Exactly, this is why I edited the file on a android phone, I can't risk moving the file onto my computer, it's already showing in the .Bat file that this file will run a script on the PC and it will take over everything, files especially and also sensitive words that looks like recovery seed.

Computers are more dangerous for crypto wallets than hardware wallet itself, before anyone says that ColdCard just proven hardware wallets wrong we can't compare running a wallet on a computer to keeping your coins on a cold storage.

Keystone messed up a bit here, they don't inform or talked about this attackers attempt, I pushed it all out but they said nothing about it, also why are hardware wallet producers holding information of their buyers? After successful sells why not wipe them off instead?
As far as I know, hardware wallet company keep invoices for years because tax requirement and shipping or fulfillment data for months just in case there is a problem with shipping but honestly I think the biggest reason most companies keep 90 day shipping data retention policy is to protect themselves from chargeback fraud and able to win dispute by proving they've shipped the stuff.

The problem is on the shipping partner anyway, they're the one that usually got hacked because sloppy system, Trezor enforced 90d data retention for shipping data and wiped it after that, yet ShipMonk hasn't deleted old data even though Trezor has repeatedly reached out to them to confirm the deletion of the data.

Ideally i'd like to see shipping data to be deleted at minimum 30d after the sales completed, this is going to limit data breach to only n+30. Saving a lot of our asses and give us peace of mind after 30 days since purchasing the hardware wallet.

..Stake.com..   ▄████████████████████████████████████▄
   ██ ▄▄▄▄▄▄▄▄▄▄            ▄▄▄▄▄▄▄▄▄▄ ██  ▄████▄
   ██ ▀▀▀▀▀▀▀▀▀▀ ██████████ ▀▀▀▀▀▀▀▀▀▀ ██  ██████
   ██ ██████████ ██      ██ ██████████ ██   ▀██▀
   ██ ██      ██ ██████  ██ ██      ██ ██    ██
   ██ ██████  ██ █████  ███ ██████  ██ ████▄ ██
   ██ █████  ███ ████  ████ █████  ███ ████████
   ██ ████  ████ ██████████ ████  ████ ████▀
   ██ ██████████ ▄▄▄▄▄▄▄▄▄▄ ██████████ ██
   ██            ▀▀▀▀▀▀▀▀▀▀            ██ 
   ▀█████████▀ ▄████████████▄ ▀█████████▀
  ▄▄▄▄▄▄▄▄▄▄▄▄███  ██  ██  ███▄▄▄▄▄▄▄▄▄▄▄▄
 ██████████████████████████████████████████
▄▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▄
█  ▄▀▄             █▀▀█▀▄▄
█  █▀█             █  ▐  ▐▌
█       ▄██▄       █  ▌  █
█     ▄██████▄     █  ▌ ▐▌
█    ██████████    █ ▐  █
█   ▐██████████▌   █ ▐ ▐▌
█    ▀▀██████▀▀    █ ▌ █
█     ▄▄▄██▄▄▄     █ ▌▐▌
█                  █▐ █
█                  █▐▐▌
█                  █▐█
▀▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▀█
▄▄█████████▄▄
▄██▀▀▀▀█████▀▀▀▀██▄
▄█▀       ▐█▌       ▀█▄
██         ▐█▌         ██
████▄     ▄█████▄     ▄████
████████▄███████████▄████████
███▀    █████████████    ▀███
██       ███████████       ██
▀█▄       █████████       ▄█▀
▀█▄    ▄██▀▀▀▀▀▀▀██▄  ▄▄▄█▀
▀███████         ███████▀
▀█████▄       ▄█████▀
▀▀▀███▄▄▄███▀▀▀
..PLAY NOW..
Pmalek
Legendary
*
Offline

Activity: 3626
Merit: 9560



View Profile
September 18, 2026, 06:45:50 AM
 #19

Exactly, this is why I edited the file on a android phone, I can't risk moving the file onto my computer, it's already showing in the .Bat file that this file will run a script on the PC and it will take over everything, files especially and also sensitive words that looks like recovery seed.
Why don't you have ChatGPT or Claude AI take a look at the script and ask them to inspect the code and tell you what exactly it does if run on Windows? You can write in the prompt that you received the file over email from a scammer because of a leaked database so that the AI has some background info. Then just ask it to explain in simple words what the script does, what it looks for on a system that runs it, and what would happen to the infected machine. Even a free AI without paid subscription will get that done for you.

▄▄███████████████████▄▄
▄███████████████████████▄
████████████████████████
█████████████████████████
████████████████████████
████████████▀██████▀████
████████████████████████
█████████▄▄▄▄███████████
██████████▄▄▄████████████
████████████████████████
████████████████▀▀███████
▀███████████████████████▀
▀▀███████████████████▀▀
 
 EARNBET 
| 🏀
 
🏈 🏓
 
🎯 🥊
 
 🎾
 
 🏐
 
🏏 🏎️
|


███████▄▄███████████
████▄██████████████████
██▀▀███████████████▀▀███
▄████████████████████████
▄▄████████▀▀▀▀▀████████▄▄██
███████████████████████████
█████████▌██▀████████████
███████████████████████████
▀▀███████▄▄▄▄▄█████████▀▀██
▀█████████████████████▀██
██▄▄███████████████▄▄███
████▀██████████████████
███████▀▀███████████

....HIGHEST....
VIP REWARDS

  G U A R A N T E E D   
| 
 🜲 
KING OF
THE CASTLE

$200K in prizes
| 
..PLAY NOW..
5W-KILO (OP)
Full Member
***
Online Online

Activity: 379
Merit: 176



View Profile
September 18, 2026, 10:35:59 AM
 #20

Exactly, this is why I edited the file on a android phone, I can't risk moving the file onto my computer, it's already showing in the .Bat file that this file will run a script on the PC and it will take over everything, files especially and also sensitive words that looks like recovery seed.
Why don't you have ChatGPT or Claude AI take a look at the script and ask them to inspect the code and tell you what exactly it does if run on Windows? You can write in the prompt that you received the file over email from a scammer because of a leaked database so that the AI has some background info. Then just ask it to explain in simple words what the script does, what it looks for on a system that runs it, and what would happen to the infected machine. Even a free AI without paid subscription will get that done for you.

Hmm, I never thought about that before, right now I guess it's too late because the official keystone team killed the scam link already, right now it's no more working, if anyone clicks it they will see error on screen about DNS domain.

I did asked them and they said it's no more trouble, sorry I was in haste to delete the Bat file, once I edited and copy paste what I found inside it I immediately deleted the file, I feel it's not that safe to leave in my phone storage.

I was never a fan of ChatGPT and other AI, this might add up to the reason why it never comes to mind to ask ChatGPT, I will close this thread very soon or not? What do you think.

Pages: [1] 2 »  All
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!