β οΈ This week, our team was targeted again.
The attack looked completely legitimate:
π² A Telegram message from someone we already knew.
π A Google Meet invitation.
π€© Then a request to switch to Microsoft Teams and "update" the application.
This wasn't an isolated case.
Over the past few weeks, we've seen several high-profile incidents:
βΊ The compromise of the official Injective SDK.
βΊ Malware distributed through fake software updates.
βΊ Blind signing, where users unknowingly approve malicious transactions.
All of these attacks have one thing in common: they rely on people trusting what they cannot verify.
A few simple security habits can significantly reduce your risk:
β
Download software only from official sources.
β
Always verify what you're signing before pressing Confirm.
β
Never grant permissions you don't fully understand.
Don't Trust. Verify.
The attack looked completely legitimate:
One of our internal security principles is never to trust something just because it looks legitimate. We analyze these kinds of attacks, understand how they work, and continuously improve our internal security policies. Thanks to that approach, we quickly discovered that the "update" could have downloaded a malicious script.
This wasn't an isolated case.
Over the past few weeks, we've seen several high-profile incidents:
All of these attacks have one thing in common: they rely on people trusting what they cannot verify.
A few simple security habits can significantly reduce your risk:
Don't Trust. Verify.
Please open Telegram to view this post
VIEW IN TELEGRAM
β‘4π±3β2π€¬1
People spend thousands of dollars securing their crypto...
Should security really work like that? We don't think so.
Our latest deep dive explains why "Don't Trust. Verify" should apply to every hardware wallet.
π Read the full article
Please open Telegram to view this post
VIEW IN TELEGRAM
π₯4π4β€1β‘1
OR macOS malware is stealing Telegram accounts and crypto wallets.
Researchers at SlowMist have uncovered a macOS infostealer that follows a five-step attack chain, ultimately giving attackers full access to a victim's Telegram account and crypto assets.
Here's how it works:
A fake "Google API Update" prompt tricks users into entering their macOS password. The malware then extracts the Chrome Safe Storage key, browser cookies, and even Apple Notes.
It copies the Telegram Desktop tdata folder, letting attackers access the victim's account on another device without a password, SMS, or 2FA.
The malware targets data from 16 crypto wallet applications, including Electrum, Exodus, Atomic Wallet, Ledger Live, Trezor Suite, and others.
Using the credentials stolen in step one, attackers attempt to decrypt encrypted wallet databases offline on their own machines - without needing continued access to the victim's computer.
The malware can replace legitimate applications with malicious versions to maintain persistence and continue stealing sensitive data.
- Never enter your macOS password into unexpected pop-up windows.
- Enable a Telegram Desktop Passcode.
- Regularly review your active Telegram sessions.
- Don't store passwords or seed phrases in Apple Notes.
- Never download wallet software or updates from links shared in chats.
Please open Telegram to view this post
VIEW IN TELEGRAM
β5π₯5β‘1π€―1
This media is not supported in your browser
VIEW IN TELEGRAM
π± $18 million. One seed phrase. One notebook.
π Food for thought.
- If someone finds your seed phrase written on paper, they find access to your crypto.
- If someone finds your metal seed backup, they find permanent access to your crypto.
- But if someone finds an ERA Recovery Card?
They'll most likely find... just a piece of plastic. And if you're using MultiShare, a single card isn't enough to recover your wallet.
βοΈSometimes the goal isn't just to back up your seed. It's to make sure that if someone finds your backup, they still can't steal your crypto.
π¬ A scene from the movie The Tuner.
In the scene, thieves try to steal a handwritten seed phrase. The owner catches them and forces them to eat the piece of paper.
Problem solved? Not really. One of the thieves memorized the seed phrase. And that's all it takes to gain full access to the crypto.
π Food for thought.
- If someone finds your seed phrase written on paper, they find access to your crypto.
- If someone finds your metal seed backup, they find permanent access to your crypto.
- But if someone finds an ERA Recovery Card?
They'll most likely find... just a piece of plastic. And if you're using MultiShare, a single card isn't enough to recover your wallet.
βοΈSometimes the goal isn't just to back up your seed. It's to make sure that if someone finds your backup, they still can't steal your crypto.
π7π₯4
ERA Wallet
π± $18 million. One seed phrase. One notebook. π¬ A scene from the movie The Tuner. In the scene, thieves try to steal a handwritten seed phrase. The owner catches them and forces them to eat the piece of paper. Problem solved? Not really. One of the thievesβ¦
Yesterday: what happens if someone steals your seed phrase.
Today: how to make sure they don't get anything useful.
π₯ Our CTO, Dan, explains how ERA Recovery protects your backup.
Today only: 30% off the [ERA Wallet + 3x ERA Recovery]
β€οΈ $158 instead of $226.
Today: how to make sure they don't get anything useful.
π₯ Our CTO, Dan, explains how ERA Recovery protects your backup.
Today only: 30% off the [ERA Wallet + 3x ERA Recovery]
Use code: TODAY30
Please open Telegram to view this post
VIEW IN TELEGRAM
YouTube
Your seed phrase on paper? One glance and it's gone #selfcustody #airdrop #crypto #coldwallet
24 words. Plain text. One mistake β one person sees it β and everyt...
π8
This media is not supported in your browser
VIEW IN TELEGRAM
π₯12β€2π1π©1
π§‘ One of our ERA Wallet users told us he now carries his wallet in a genuine leather sleeve handcrafted by his wife.
βΊοΈ Thank you for sharing these moments with us. Honestly, every time we receive your photos, stories, or even a simple message about how you use your ERA Wallet, we get just as excited as kids
Keep them coming! We absolutely love seeing how ERA becomes part of your story π«°π½
Moments like these remind us that we're building more than just a device - we're creating something that becomes part of people's everyday lives.
Keep them coming! We absolutely love seeing how ERA becomes part of your story π«°π½
Please open Telegram to view this post
VIEW IN TELEGRAM
β€7π4π₯1
This is a special milestone for us.
Over the years, Sparrow Wallet has earned its place as one of the most trusted Bitcoin wallets in the community, built for people who value self-custody, transparency, and security.
Starting today, Sparrow users can use ERA Wallet as an air-gapped signing device for Bitcoin transactions.
Why it matters:
A huge thank you to the @SparrowWallet team for making this possible! π€
This is just the beginning - more integrations and exciting updates are on the way. π
Please open Telegram to view this post
VIEW IN TELEGRAM
π₯10π2β€1
π A few words from our founder, Alex, on the recent Coldcard incident.
For those who prefer reading, here's the transcript π
Love you allπ The ERA Team
For those who prefer reading, here's the transcript π
Hey everyone π
By now you've probably all seen the news about the Coldcard incident. Honestly, it's a tough reminder that even in self-custody, security can never be taken for granted.
As for ERA Wallet, most of you already know how key generation works here. We use 5 independent entropy sources:
β’ 2 hardware TRNGs (Secure Element + MCU)
β’ 3 entropy sources influenced directly by you (camera, screen swipes, and device motion)
On top of that, ERA performs a mathematical entropy quality check (Shannon entropy estimation) before allowing wallet generation. If the randomness isn't good enough, the wallet simply won't be created.π± I also hope we're getting close to the end of all the patent and documentation work. Once that's behind us, we'll finally move toward becoming an open-source project, and everyone will be able to verify exactly how everything works.
βοΈOne more thing.
Please take every hack and every security incident seriously. Not because you should panic - but because every incident is a chance to improve your own security.
A few simple recommendations:
β’ Don't keep your entire portfolio behind a single seed phrase.
β’ Diversify your risk whenever possible.
β’ Protect your backups and never rely on memory alone.
β’ Be careful about what you install on your computer and phone.
β’ Always verify what you're signing.
π€¦π½ More and more attacks today exploit the human factor rather than cryptography itself.
Stay safe. We'll keep doing everything we can to make self-custody safer and easier for everyone.
Love you all
Please open Telegram to view this post
VIEW IN TELEGRAM
π6β€3β1π₯1π1π―1
This media is not supported in your browser
VIEW IN TELEGRAM
Following the recent Coldcard incident, we decided not to stop at words.
π΄ Today we're publishing a detailed breakdown of how ERA generates your seed using up to five independent entropy sources.
β¬οΈ A quick message from our CTO, Dan, about today's article and our next step.
And this is just the beginning.
Please open Telegram to view this post
VIEW IN TELEGRAM
π₯7π2
Please open Telegram to view this post
VIEW IN TELEGRAM
π₯7β4π2
As promised, here's the first part.
We've published a detailed deep dive into how ERA Wallet generates your seed using up to five independent entropy sources.
π° Read the full article here: [link]
Tomorrow we go further: raw data, NIST tests, and a notebook you can run yourself.
What do you think about this level of transparency? π
We've published a detailed deep dive into how ERA Wallet generates your seed using up to five independent entropy sources.
Tomorrow we go further: raw data, NIST tests, and a notebook you can run yourself.
What do you think about this level of transparency? π
Please open Telegram to view this post
VIEW IN TELEGRAM
π₯9π6π¨βπ»2
The truth is, there isn't one perfect software wallet.
Different people value different things:
β’ supported blockchains
β’ interface
β’ staking
β’ swaps
β’ ecosystem
And that's exactly how it should be.
But one thing shouldn't change:
That's why we believe a hardware wallet should work with the software wallet you choose.
Please open Telegram to view this post
VIEW IN TELEGRAM
π₯8π―3π1
Most manufacturers point to chip certifications. We decided to test the wallet itself.
Over the past week, we built an automated test bench and evaluated an ERA Wallet through a proper scientific evaluation:
We also created five intentionally broken random number generators and ran them through the exact same pipeline to verify that our methodology could actually detect failures - not just produce green checkmarks. Four were caught immediately. One wasn't.
That last result turned out to be one of the most interesting findings of the entire research.
The full report includes raw data, methodology, source code, and reproducible results, so anyone can verify every graph and every conclusion themselves.
Security shouldn't rely on trust.
Please open Telegram to view this post
VIEW IN TELEGRAM
π¨βπ»6π4π2π₯2
We believe your hardware wallet should work with the software wallet that fits your needs.
Why Guarda?βΊ 70+ blockchainsβΊ Built-in swapsβΊ StakingβΊ Desktop, mobile, web & extension
Everything you need to manage your assets in one place.
Guarda users can now connect ERA Wallet and keep their private keys securely offline while continuing to manage assets through the interface they already know.
π Connect it to ERA Wallet in just a few minutes.
Please open Telegram to view this post
VIEW IN TELEGRAM
π₯8β€2π1π1π±1
π Today: #LetsTalkCrypto Hardware Wallet AMA
Today, ERA Wallet joins LetsExchange and Ryder Wallet to discuss the future of hardware wallets.
β± 2 PM UTC
π€© X Spaces
π Join us: https://x.com/i/spaces/1NGarorjWYEJj?s=20
Today, ERA Wallet joins LetsExchange and Ryder Wallet to discuss the future of hardware wallets.
Weβll talk about:βΊ What friction hardware wallets should removeβΊ How Quick Sign simplifies wallet selectionβΊ How clearly DeFi actions should be explained on-deviceβΊ What should always remain visible to the userβΊ Whether AI-powered warnings belong on hardware wallets
π Join us: https://x.com/i/spaces/1NGarorjWYEJj?s=20
Please open Telegram to view this post
VIEW IN TELEGRAM
π5β€3π3β‘2π₯1