The post Why did I receive a Trezor phishing email from Substack? appeared on BitcoinEthereumNews.com. Last night I was unfortunate enough to join the long list of individuals who have been targeted by crude phishing attempts claiming to be from hardware wallet maker Trezor. This email, which had the subject line “Quantum Vulnerability Disclosure,” claimed that it was notifying me of a new firmware for my wallet that would help protect it against a fictitious exploit rooted in “recent breakthroughs in quantum technology” that “have revealed vulnerabilities in existing encryption.” The email encouraged me to “take immediate action to protect [my] information” by making sure to upgrade my device’s firmware. Read more: Crypto phishing blitz hits CoinMarketCap, Cointelegraph, and Trezor It falsely claimed that the upgrade was “necessary to safeguard your assets and prevent exposure to these evolving threats.” The most interesting thing about the email, however, was that it wasn’t from Trezor but rather [email protected]. How it works Greg Lockard runs the Greg Expectations newsletter in which he provides “updates about the comic books and graphic novels I am working on as both a writer and an editor.” According to a follow-up email that was sent from his Substack after the apparent compromise, he encouraged his subscribers to ignore the phishing email, noting that his Substack was hacked and claiming he was working with Substack to rectify the problem. Once Lockard’s Substack was hacked, it appears it was possible for the hacker to add emails to its list, a feature intended to make it easier for creators to import their email lists from other platforms. This meant that even though I wasn’t previously a subscriber, they were able to add me as one without confirmation. Screenshot from one of the emails. The hacker was aided in their quest to target crypto users by Trezor’s security failures, with a third-party support portal it used being… The post Why did I receive a Trezor phishing email from Substack? appeared on BitcoinEthereumNews.com. Last night I was unfortunate enough to join the long list of individuals who have been targeted by crude phishing attempts claiming to be from hardware wallet maker Trezor. This email, which had the subject line “Quantum Vulnerability Disclosure,” claimed that it was notifying me of a new firmware for my wallet that would help protect it against a fictitious exploit rooted in “recent breakthroughs in quantum technology” that “have revealed vulnerabilities in existing encryption.” The email encouraged me to “take immediate action to protect [my] information” by making sure to upgrade my device’s firmware. Read more: Crypto phishing blitz hits CoinMarketCap, Cointelegraph, and Trezor It falsely claimed that the upgrade was “necessary to safeguard your assets and prevent exposure to these evolving threats.” The most interesting thing about the email, however, was that it wasn’t from Trezor but rather [email protected]. How it works Greg Lockard runs the Greg Expectations newsletter in which he provides “updates about the comic books and graphic novels I am working on as both a writer and an editor.” According to a follow-up email that was sent from his Substack after the apparent compromise, he encouraged his subscribers to ignore the phishing email, noting that his Substack was hacked and claiming he was working with Substack to rectify the problem. Once Lockard’s Substack was hacked, it appears it was possible for the hacker to add emails to its list, a feature intended to make it easier for creators to import their email lists from other platforms. This meant that even though I wasn’t previously a subscriber, they were able to add me as one without confirmation. Screenshot from one of the emails. The hacker was aided in their quest to target crypto users by Trezor’s security failures, with a third-party support portal it used being…

Why did I receive a Trezor phishing email from Substack?

2025/10/18 00:33
3분 읽기
이 콘텐츠에 대한 의견이나 우려 사항이 있으시면 crypto.news@mexc.com으로 연락주시기 바랍니다

Last night I was unfortunate enough to join the long list of individuals who have been targeted by crude phishing attempts claiming to be from hardware wallet maker Trezor.

This email, which had the subject line “Quantum Vulnerability Disclosure,” claimed that it was notifying me of a new firmware for my wallet that would help protect it against a fictitious exploit rooted in “recent breakthroughs in quantum technology” that “have revealed vulnerabilities in existing encryption.”

The email encouraged me to “take immediate action to protect [my] information” by making sure to upgrade my device’s firmware.

Read more: Crypto phishing blitz hits CoinMarketCap, Cointelegraph, and Trezor

It falsely claimed that the upgrade was “necessary to safeguard your assets and prevent exposure to these evolving threats.”

The most interesting thing about the email, however, was that it wasn’t from Trezor but rather [email protected].

How it works

Greg Lockard runs the Greg Expectations newsletter in which he provides “updates about the comic books and graphic novels I am working on as both a writer and an editor.”

According to a follow-up email that was sent from his Substack after the apparent compromise, he encouraged his subscribers to ignore the phishing email, noting that his Substack was hacked and claiming he was working with Substack to rectify the problem.

Once Lockard’s Substack was hacked, it appears it was possible for the hacker to add emails to its list, a feature intended to make it easier for creators to import their email lists from other platforms.

This meant that even though I wasn’t previously a subscriber, they were able to add me as one without confirmation.

Screenshot from one of the emails.

The hacker was aided in their quest to target crypto users by Trezor’s security failures, with a third-party support portal it used being compromised in 2024.

Users who received this email and then clicked the “Upgrade Firmware” button in the newsletter were directed to quantumshield-trezor[dot]io, which is currently unavailable.

This domain would presumably host the website that would encourage users to either install malware or attempt to trick them into revealing their seed phrase.

Protos reached out to Substack to determine what steps they take to prevent this type of attack and how this one specifically managed to avoid it, but it did not immediately respond.

Do we need to be worried about quantum vulnerability?

While quantum computers are still progressing and may eventually pose a threat to a variety of encryption types currently in use, as it stands, the systems are expensive and lack the capacity to break most encryption.

Once quantum computers are deployed, they’ll be controlled by a small number of actors and will likely initially focus on a small number of targets.

Read more: The internet is laughing at El Salvador’s ‘quantum-safe’ bitcoin | Protos

There is also active and substantial development work underway on various chains in an effort to come up with mitigation strategies to reduce the likelihood of these attacks being successful.

In general, be extraordinarily cautious whenever any email or website suggests that you need to give it access to your wallets. Phishing is a much larger risk than quantum computing at this time and for the near future.

Got a tip? Send us an email securely via Protos Leaks. For more informed news, follow us on X, Bluesky, and Google News, or subscribe to our YouTube channel.

Source: https://protos.com/why-did-i-receive-a-trezor-phishing-email-from-substack/

시장 기회
Ambire Wallet 로고
Ambire Wallet 가격(WALLET)
$0.01176
$0.01176$0.01176
-1.25%
USD
Ambire Wallet (WALLET) 실시간 가격 차트
면책 조항: 본 사이트에 재게시된 글들은 공개 플랫폼에서 가져온 것으로 정보 제공 목적으로만 제공됩니다. 이는 반드시 MEXC의 견해를 반영하는 것은 아닙니다. 모든 권리는 원저자에게 있습니다. 제3자의 권리를 침해하는 콘텐츠가 있다고 판단될 경우, crypto.news@mexc.com으로 연락하여 삭제 요청을 해주시기 바랍니다. MEXC는 콘텐츠의 정확성, 완전성 또는 시의적절성에 대해 어떠한 보증도 하지 않으며, 제공된 정보에 기반하여 취해진 어떠한 조치에 대해서도 책임을 지지 않습니다. 본 콘텐츠는 금융, 법률 또는 기타 전문적인 조언을 구성하지 않으며, MEXC의 추천이나 보증으로 간주되어서는 안 됩니다.

$30,000 in PRL + 15,000 USDT

$30,000 in PRL + 15,000 USDT$30,000 in PRL + 15,000 USDT

Deposit & trade PRL to boost your rewards!