Hackers build like-for-like open-source app to try and steal crypto

Hacker hacking on a laptop.
(Image credit: GETTY - boonchai wedmakawand)

Phishing attacks have already been proven to be a danger to all kinds of PC users in 2022 but are especially rampant in crypto and NFT spaces. We've already seen scammers use Discord to try to steal cryptocurrencies, and NFTs swindled in the OpenSea phishing scam.

Now the cryptocurrency wallet provider, Trezor has found its users under attack. Reported by Bleeping Computer, Trezor's mailing list was used to target users, and trick them into downloading a fake version of the software designed to steal their crypto assets.

The original Trezor software is open source, so the code is available to download and in this case be manipulated by others. It's likely this spoofed version is just very so slightly changed from the original as it still even has the Trezor banner warning customers to beware of phishing scams.

Once downloaded, the software asks for a recovery phrase that would have been set by the user when setting up their wallet the first time. This recovery phrase acts as a key to get back into the wallet if lost. Once the user enters the key, then it's game over. The recovery phrase is sent back to the scammers who can now claim all your crypto assets for themselves.

Window shopping

Windows 11 Square logo

(Image credit: Microsoft)

Windows 11 review: What we think of the new OS
How to install Windows 11: Safe and secure install
What you need to know before upgrading: Things to note before downloading the latest OS
Windows 11 TPM requirements: Microsoft's strict security policy

It goes without saying that you should always be incredibly careful using recovery keys for anything online. With phishing scams this sophisticated it can be incredibly difficult to tell a legitimate site or program from a fake. Even the websites associated with the download for this particular scam looked legitimate due to the use of special characters. It's always a good idea to double check anything asking for a security key or password, there are absolutely dragons out there. 

Trezor believes this particular dragon targeted one of its newsletters hosted on the automated email platform Mailchimp and was co-opted for nefarious purposes. Trezor also stated in a tweet that Mailchimp confirmed that an insider had targeted crypto companies, but there's yet to be a statement from Mailchimp itself on the issue.

For now it's best to treat every email with a bit of suspicion, and definitely do a few checks before handing over any information, or installing files onto your PC. Logging into the service normally on a different browser or machine is always a smart step if something looks suspicious. Typing links manually instead of clicking on them, and double checking them against the known website is also a good move to avoid trouble.

With all these hacks targeting crypto currencies in particular, it could be that avoiding them all together may also be the best way to stay safe out there in these interesting times. And don't forget to update your passwords!

Hope Corrigan
Hardware Writer

Hope’s been writing about games for about a decade, starting out way back when on the Australian Nintendo fan site Vooks.net. Since then, she’s talked far too much about games and tech for publications such as Techlife, Byteside, IGN, and GameSpot. Of course there’s also here at PC Gamer, where she gets to indulge her inner hardware nerd with news and reviews. You can usually find Hope fawning over some art, tech, or likely a wonderful combination of them both and where relevant she’ll share them with you here. When she’s not writing about the amazing creations of others, she’s working on what she hopes will one day be her own. You can find her fictional chill out ambient far future sci-fi radio show/album/listening experience podcast right here. No, she’s not kidding. 

Read more
An image of a fake Bitcoin with a laptop in the background displaying financial data
North Korean hackers are said to have stolen $1,300,000,000 in crypto in 2024, an estimated 61% of the total funds swiped this year
Hacker
$1.5 billion crypto heist could be the biggest yet, more than doubling the previous record, but don't worry: The affected firm says it can take the hit
Kinzie, in an FBI jacket, uses a computer with the logo of the Third Street Saints on it
Have I Been Pwned adds over 284 million compromised passwords from latest breach
 In this photo illustration a novelty Bitcoin token is photographed on a US Dollar bank note, on January 4, 2025 in Bath, England. The Cryptocurrency market has recently received a significant boost by the election of Donald Trump with hopes of the start of a policy framework that could see Bitcoin as a strategic asset
Man charged with $65,000,000 worth of cryptocurrency heists was reportedly discovered through chatting on Discord with a company they allegedly stole from
Steam logo
A web3 free-to-play survival game found to be a front for installing malware on your PC has finally been removed from Steam
Mister Fantastic giving a thumbs up
A Marvel Rivals player has uncovered 'one of the most dangerous vulnerabilities a game can have' that'll let cheaters take over your PC and find your passwords
Latest in Security
An FBI wanted poster for alleged hacker Zhou Shuai.
US Justice Dept announces $10 million bounty on at-large 'hacker-for-hire' cabal it says targeted China critics, religious missionaries, and the Treasury
Kinzie, in an FBI jacket, uses a computer with the logo of the Third Street Saints on it
Have I Been Pwned adds over 284 million compromised passwords from latest breach
A still from a YouTube video of Senator Mark Warner speaking
Telecoms hack on US government officials is 'worst in nations history' and 'the barn door is still wide open' says senator
HDMI cable
Hackers can wirelessly spy on your display by collecting HDMI signal leaks and churning them through an AI, but I wouldn't break out the tin foil just yet
Computer code and text displayed on computer screens. Photographer: Chris Ratcliffe/Bloomberg
Forcing users to periodically change their passwords should go the way of the dodo according to the US government
An original Apple Macintosh Model M0001, as they celebrate 40th anniversary, is on display in between 2024 Apple models at the independent Apple products store chain Amac, on January 24, 2024 in Utrecht, The Netherlands. Based on the Motorola 68000 microprocessor, the Macintosh was the first successful mouse-driven computer with a graphical user interface.
Major browser providers scramble to patch an 18-year-old vulnerability affecting MacOS and Linux systems but Windows remains gloriously immune
Latest in News
Silent Hill f transmission trailer screenshots
'We've been keeping fans waiting for an awfully long time': We finally got to see more of Silent Hill f and boy, does it look great
A goblin with sharp teeth, wearing goggles, lets out a mischievous cackle in WoW's latest patch: Undermine(d).
The hooligan hacker guild that tore up WoW's newest raid (twice) just posted video evidence of the whole thing, and it's got me feeling weirdly nostalgic
A pasta "display" on a table showing the word "keep" surrounded by fruit. Obviously.
Penne for your thoughts: This pasta display can show three individual frames and it's trying its best, okay
Intel engineers inspect a lithography machine
Finally some good vibes from Intel as stock jumps 15% on new CEO hire and Arizona fab celebrates 'Eagle has landed' moment for its 18A node
Commander Shepard in Mass Effect 3.
Mass Effect's Jennifer Hale, who played femshep, 'saw no line' before she recorded them for Bioware's flagship trilogy: 'It was all cold reading on the spot'
A side by side comparison of two Asus Q-Release systems, with the original design on the top and the bottom showing the apparently new design.
Asus appears to have quietly changed the design of its Q-Release PCIe slot after claims of potential GPU pin damage