2.25: Dark Skippy Scam

This scam targets holders of hardware wallets such as Ledger or Trezor. Malware loaded onto your hardware device uses a low-entropy signing function that incorporates the seed phrase into the hash of a signed transaction. A brute-force attack on that hash can then reverse-engineer the seed phrase, giving the attacker full access to all private keys derived from it.

The key takeaway: it is your responsibility to ensure malware is never loaded onto your hardware wallet by only ever updating the firmware using the official app relevant to your wallet.

If you have any doubts, simply wiping your hardware wallet is not sufficient — your seed phrase may already be out there. The only way to be safe is to set up a brand-new wallet and move your cryptos there.

Please feel free to contact us with any questions.