A phishing email is being sent out impersonating Blockstream. As we investigate, please remember:

1️⃣ DO NOT click on any suspicious emails claiming to be from Blockstream. Blockstream will NEVER ask for personal information via email.

2️⃣ NEVER enter your seed phrase online or share it with anyone, even if they claim to be from the Blockstream support team.

You should only update your Jade firmware through the #BlockstreamGreen wallet application or our dedicated firmware website ⬇️

https://jadefw.blockstream.com/upgrade/fwupgrade.html

Reply to this note

Please Login to reply.

Discussion

could u guys put Adam's real npub in description of nostr profile of blockstream

I don't think Adam uses nostr much. Last post was in July.

yes - other in Blockstream boarder team do - so bots try to benefit his dormant mode for now

Probably shouldn’t click this link either 🤷‍♂️

I see "urgent firmware/software update" anywhere the red lights go off right away.

who leaked the customer email addresses ?

The information that was hacked in 2020.

https://haveibeenpwned.com/PwnedWebsites

The reason I mention it is because maybe it's someone using the Ledger list? I didn't get the email, but I didn't have a ledger account till after the leak and I've had a blockstream account for a while now.

If it was full blockstream hack/leak, I should have seen an email.

Putting two and two together, although they may not add up. Hah.

Well someone confirmed their one time use email was emailed, so that kinda seals where it came from.

Dang it... one time use email for the online store*

I dont use a jade but I bought a shirt from them and I got the email.

”ブロックストリームを装ったフィッシングメールが送信されています。調査を行いますので、くれぐれもご注意ください:

1️ ⃣ Blockstream を名乗る不審なメールは絶対にクリックしないでください。Blockstream が電子メールで個人情報を尋ねることは決してありません。

2️ ȃ たとえブロックストリームのサポート・チームを名乗る人物であっても、決して自分のシード・フレーズをオンラインで入力したり、誰かに教えたりしないでください。”

nostr:nevent1qqsrndvlzjknrhfjupq6tves2h2lnv3068hk9gdxjvpzrfrman7ywecpz4mhxue69uhk2er9dchxummnw3ezumrpdejqz9mhwden5te0dehhxarj9enx6apwwa5h5tnzd9aqz9rhwden5te0wfjkccte9ejxzmt4wvhxjmcpr4mhxue69uhkummnw3ez6ur4vgh8wetvd3hhyer9wghxuet5qyf8wumn8ghj7mmxve3ksctfdch8qatzqyxhwumn8ghj7mn0wvhxcmmvqyv8wumn8ghj7un9d3shjtnndehhyapwwdhkx6tpdsq3wamnwvaz7tmjv4kxz7fwvd6hyun9de6zuenedyqs7amnwvaz7tmndakx7cm09ehxcqgkwaehxw309ashgmrpwvhxummnw3ezumrpdejqnw9qn8

Received the email this morning and checked the sender, it was not a Blockstream email address so I knew immediately it was a scam

Good job

Is this another Ledger-type data breach situation or something else?

Rogue employee?

Do we need to switch wallets again? Ffs

2️⃣ NEVER enter your seed phrase online or share it with anyone, even if they ~~claim to be~~ **are** from the Blockstream support team.

RIP a los correos electrónicos

People should beware of phishing emails

Has there been a breach of subscriber email addresses?

We are still investigating the issue. Early indicators, like customers who made purchases from our store not receiving emails, suggest this could be a targeted phishing attempt against Bitcoin users or a broader spam campaign. Similar emails from the same source are also targeting services from several companies that have previously offered Bitcoin-related products.

I didn’t get this email either.

But Reddit has a number of posts talking about similar activities with all types of wallets and exchanges. Mostly in the past month.

Everything related with crypto spam I blame ledger leak

We are actively collaborating with other companies to take-down the ongoing phishing campaign.

So far via the registrar, we were able to deactivate and then take possession of the http://secure-blockstream.com domain, which was implicated in the phishing efforts.

Our team is currently investigating the source of this data to assess whether additional information has been compromised.

Preliminary results are inconclusive, as we've encountered examples that don't match any specific data set.

If you've received such a phishing email, it would be helpful if you would please forward it and any information you think maybe relevant to support@blockstream.com

I knew the free elephant was too good to be true