ERA Wallet
1.6K subscribers
260 photos
51 videos
6 files
223 links
A direct line to the ERA team. Security updates before they're public, straight from the people who build it.

🌐 https://era-wallet.com
Group @EraWalletchat
Support @ERAwlt_support_bot
Download Telegram
⚠️ This week, our team was targeted again.

The attack looked completely legitimate:
πŸ“² A Telegram message from someone we already knew.
🎞 A Google Meet invitation.
🀩 Then a request to switch to Microsoft Teams and "update" the application.

One of our internal security principles is never to trust something just because it looks legitimate. We analyze these kinds of attacks, understand how they work, and continuously improve our internal security policies. Thanks to that approach, we quickly discovered that the "update" could have downloaded a malicious script.


This wasn't an isolated case.
Over the past few weeks, we've seen several high-profile incidents:
⏺ The compromise of the official Injective SDK.
⏺ Malware distributed through fake software updates.
⏺ Blind signing, where users unknowingly approve malicious transactions.

All of these attacks have one thing in common: they rely on people trusting what they cannot verify.
A few simple security habits can significantly reduce your risk:
βœ… Download software only from official sources.
βœ… Always verify what you're signing before pressing Confirm.
βœ… Never grant permissions you don't fully understand.

Don't Trust. Verify.
Please open Telegram to view this post
VIEW IN TELEGRAM
⚑4😱3✍2🀬1
πŸ”΄ This article may ruin your trust in your hardware wallet.

People spend thousands of dollars securing their crypto...
⏺ then blindly approve transactions they can't read.
⏺ Or trust that their wallet wasn't modified before it reached them.
⏺ Or simply hope their private keys were generated correctly.

Should security really work like that? We don't think so.

Our latest deep dive explains why "Don't Trust. Verify" should apply to every hardware wallet.

πŸ“– Read the full article
Please open Telegram to view this post
VIEW IN TELEGRAM
πŸ”₯4πŸ‘€4❀1⚑1
🚨 Scam Breakdown #02
OR macOS malware is stealing Telegram accounts and crypto wallets.

Researchers at SlowMist have uncovered a macOS infostealer that follows a five-step attack chain, ultimately giving attackers full access to a victim's Telegram account and crypto assets.


Here's how it works:
⏺Password harvesting
A fake "Google API Update" prompt tricks users into entering their macOS password. The malware then extracts the Chrome Safe Storage key, browser cookies, and even Apple Notes.
⏺Telegram takeover
It copies the Telegram Desktop tdata folder, letting attackers access the victim's account on another device without a password, SMS, or 2FA.
⏺Wallet database theft
The malware targets data from 16 crypto wallet applications, including Electrum, Exodus, Atomic Wallet, Ledger Live, Trezor Suite, and others.
⏺Offline decryption
Using the credentials stolen in step one, attackers attempt to decrypt encrypted wallet databases offline on their own machines - without needing continued access to the victim's computer.
⏺Application replacement
The malware can replace legitimate applications with malicious versions to maintain persistence and continue stealing sensitive data.

⚠️ Stay protected:
- Never enter your macOS password into unexpected pop-up windows.
- Enable a Telegram Desktop Passcode.
- Regularly review your active Telegram sessions.
- Don't store passwords or seed phrases in Apple Notes.
- Never download wallet software or updates from links shared in chats.

πŸ‘Don't Trust. Verify.
Please open Telegram to view this post
VIEW IN TELEGRAM
✍5πŸ”₯5⚑1🀯1
This media is not supported in your browser
VIEW IN TELEGRAM
🌱 $18 million. One seed phrase. One notebook.

🎬 A scene from the movie The Tuner.
In the scene, thieves try to steal a handwritten seed phrase. The owner catches them and forces them to eat the piece of paper.
Problem solved? Not really. One of the thieves memorized the seed phrase. And that's all it takes to gain full access to the crypto.


πŸ’­ Food for thought.
- If someone finds your seed phrase written on paper, they find access to your crypto.
- If someone finds your metal seed backup, they find permanent access to your crypto.
- But if someone finds an ERA Recovery Card?
They'll most likely find... just a piece of plastic. And if you're using MultiShare, a single card isn't enough to recover your wallet.

❗️Sometimes the goal isn't just to back up your seed. It's to make sure that if someone finds your backup, they still can't steal your crypto.
πŸ‘7πŸ”₯4
No way this became ERA Wallet... πŸ˜…

That was one of our very first working prototypes. Today it looks a little different.

Progress isn't magic. It's iteration.


πŸŽ™ Alex, your turn. What's the first thing that comes to mind when you look at this?
πŸ”₯11🀩2🍾2πŸ€“1πŸ™Š1
This media is not supported in your browser
VIEW IN TELEGRAM
πŸ”₯12❀2πŸ‘1πŸ’©1
🧑 One of our ERA Wallet users told us he now carries his wallet in a genuine leather sleeve handcrafted by his wife.

Moments like these remind us that we're building more than just a device - we're creating something that becomes part of people's everyday lives.


☺️ Thank you for sharing these moments with us. Honestly, every time we receive your photos, stories, or even a simple message about how you use your ERA Wallet, we get just as excited as kids

Keep them coming! We absolutely love seeing how ERA becomes part of your story 🫰🏽
Please open Telegram to view this post
VIEW IN TELEGRAM
❀7πŸ‘4πŸ”₯1
⚑ERA Wallet is now supported by Sparrow Wallet
This is a special milestone for us.

Over the years, Sparrow Wallet has earned its place as one of the most trusted Bitcoin wallets in the community, built for people who value self-custody, transparency, and security.


Starting today, Sparrow users can use ERA Wallet as an air-gapped signing device for Bitcoin transactions.

Why it matters:
⏺ Fully offline transaction signing via QR codes - no USB, Bluetooth, or Wi-Fi.
⏺ Your private keys never leave the device.
⏺ More choice for Bitcoiners who prefer secure self-custody.

A huge thank you to the @SparrowWallet team for making this possible! 🀝

This is just the beginning - more integrations and exciting updates are on the way. πŸš€
Please open Telegram to view this post
VIEW IN TELEGRAM
πŸ”₯10πŸ‘2❀1
πŸ‘6πŸ”₯1
πŸŽ™ A few words from our founder, Alex, on the recent Coldcard incident.
For those who prefer reading, here's the transcript πŸ‘‡

Hey everyone πŸ™‚
By now you've probably all seen the news about the Coldcard incident. Honestly, it's a tough reminder that even in self-custody, security can never be taken for granted.

As for ERA Wallet, most of you already know how key generation works here. We use 5 independent entropy sources:
β€’ 2 hardware TRNGs (Secure Element + MCU)
β€’ 3 entropy sources influenced directly by you (camera, screen swipes, and device motion)

On top of that, ERA performs a mathematical entropy quality check (Shannon entropy estimation) before allowing wallet generation. If the randomness isn't good enough, the wallet simply won't be created.

🐱 I also hope we're getting close to the end of all the patent and documentation work. Once that's behind us, we'll finally move toward becoming an open-source project, and everyone will be able to verify exactly how everything works.

❗️One more thing.
Please take every hack and every security incident seriously. Not because you should panic - but because every incident is a chance to improve your own security.

A few simple recommendations:
β€’ Don't keep your entire portfolio behind a single seed phrase.
β€’ Diversify your risk whenever possible.
β€’ Protect your backups and never rely on memory alone.
β€’ Be careful about what you install on your computer and phone.
β€’ Always verify what you're signing.

🀦🏽 More and more attacks today exploit the human factor rather than cryptography itself.
Stay safe. We'll keep doing everything we can to make self-custody safer and easier for everyone.


Love you all πŸ‘ The ERA Team
Please open Telegram to view this post
VIEW IN TELEGRAM
πŸ‘6❀3✍1πŸ”₯1πŸ™1πŸ’―1
This media is not supported in your browser
VIEW IN TELEGRAM
Following the recent Coldcard incident, we decided not to stop at words.

πŸ”΄ Today we're publishing a detailed breakdown of how ERA generates your seed using up to five independent entropy sources.

And this is just the beginning.


⬇️ A quick message from our CTO, Dan, about today's article and our next step.
Please open Telegram to view this post
VIEW IN TELEGRAM
πŸ”₯7πŸ‘2
This media is not supported in your browser
VIEW IN TELEGRAM
πŸ”₯11πŸ‘2❀1
⏺ Later today, we publish a detailed article explaining how randomness is generated in ERA Wallet.
⏺ Tomorrow, we put that claim to the test - an open experiment on our hardware randomness, with the raw data, the NIST test results, and a public Google Colab notebook, so anyone can verify the results.
Please open Telegram to view this post
VIEW IN TELEGRAM
πŸ”₯7✍4πŸ‘Œ2
As promised, here's the first part.
We've published a detailed deep dive into how ERA Wallet generates your seed using up to five independent entropy sources.

πŸ“° Read the full article here: [link]

Tomorrow we go further: raw data, NIST tests, and a notebook you can run yourself.

What do you think about this level of transparency? πŸ‘‡
Please open Telegram to view this post
VIEW IN TELEGRAM
πŸ”₯9πŸ‘6πŸ‘¨β€πŸ’»2
πŸ“Š 62% of crypto users now manage two or more wallets, using different apps for different blockchains, ecosystems, and use cases.
The truth is, there isn't one perfect software wallet.

Different people value different things:
β€’ supported blockchains
β€’ interface
β€’ staking
β€’ swaps
β€’ ecosystem

And that's exactly how it should be.
But one thing shouldn't change:
πŸ”΄ Your private keys should stay offline.

That's why we believe a hardware wallet should work with the software wallet you choose.
πŸ‘€ Stay tuned
Please open Telegram to view this post
VIEW IN TELEGRAM
πŸ”₯8πŸ’―3πŸ‘1
❓ How random are the numbers your hardware wallet builds your seed from?
Most manufacturers point to chip certifications. We decided to test the wallet itself.

Over the past week, we built an automated test bench and evaluated an ERA Wallet through a proper scientific evaluation:
⏺ NIST SP 800-90B
⏺ NIST SP 800-22
⏺ BSI AIS-31
⏺ PractRand
⏺ 1,000 cold boot cycles

πŸ”΄But we didn't stop there.
We also created five intentionally broken random number generators and ran them through the exact same pipeline to verify that our methodology could actually detect failures - not just produce green checkmarks. Four were caught immediately. One wasn't.
That last result turned out to be one of the most interesting findings of the entire research.


The full report includes raw data, methodology, source code, and reproducible results, so anyone can verify every graph and every conclusion themselves.
Security shouldn't rely on trust.

πŸ“– Full research
Please open Telegram to view this post
VIEW IN TELEGRAM
πŸ‘¨β€πŸ’»6πŸ‘€4πŸ‘2πŸ”₯2
Well, now we want you to tag us more often πŸ₯Ή
You really do make our team so happy 🧑
πŸ”₯13❀3πŸ‘3πŸ’―2
❗️ Self-custody shouldn't lock you into a single app.

We believe your hardware wallet should work with the software wallet that fits your needs.

πŸŽ† Today we're excited to announce support for Guarda Wallet.

Why Guarda?
⏺ 70+ blockchains
⏺ Built-in swaps
⏺ Staking
⏺ Desktop, mobile, web & extension
Everything you need to manage your assets in one place.


Guarda users can now connect ERA Wallet and keep their private keys securely offline while continuing to manage assets through the interface they already know.

πŸ‘‰ Connect it to ERA Wallet in just a few minutes.
πŸ” Not using Guarda yet? It might be the perfect time to explore it.
Please open Telegram to view this post
VIEW IN TELEGRAM
πŸ”₯8❀2πŸ‘1πŸ‘1😱1
πŸš€ Today: #LetsTalkCrypto Hardware Wallet AMA

Today, ERA Wallet joins LetsExchange and Ryder Wallet to discuss the future of hardware wallets.

We’ll talk about:
⏺ What friction hardware wallets should remove
⏺ How Quick Sign simplifies wallet selection
⏺ How clearly DeFi actions should be explained on-device
⏺ What should always remain visible to the user
⏺ Whether AI-powered warnings belong on hardware wallets


⏱ 2 PM UTC
🀩 X Spaces
πŸ‘‰ Join us: https://x.com/i/spaces/1NGarorjWYEJj?s=20
Please open Telegram to view this post
VIEW IN TELEGRAM
πŸ‘5❀3πŸ†’3⚑2πŸ”₯1