🧑‍💻👻🔥
We created a video about the new contributers page and everything you need to know if you want to help the @SpecterDIY or @SpecterWallet Desktop project.
1
130
SpecterWallet retweeted
Currently the email providers of several Bitcoin projects, incl. two hardware wallet firms, were compromised. Phishing emails are circulating. Affected provider: Brevo. Our newsletter subscribers and specter.solutions are not affected by this incident. We use EmailOctopus
🚨 SECURITY WARNING 🚨 Brevo (formerly Sendinblue) has reportedly been compromised. Phishing emails impersonating CoinTracking, Trezor and BitBox and likely several others in the industry are currently making the rounds. DO NOT: ❌ Click any links ❌ Download attachments ❌ Enter your seed phrase anywhere online Your seed NEVER belongs on a website. Ever. Please warn others.
2
3
10
1,272
If you want to contribute to Specter Desktop, you will find everything you need here. You can contribute to our core Specter Desktop Companion App or build plugins that integrate with Specter Desktop.
I added a page on how to contribute to our official @SpecterDIY and @SpecterWallet Desktop website: specter.solutions/contribute Here you will find: - All relevant Telegram groups - Information for Specter Desktop contribution - Links to the Specter GitHub as well as our Playground draft for Specter 3.0 firmware with new UI/UX - Link to our YouTube channel and the livestream call on YouTube Thursday at 17:00 - Quick guide on how to test the newest PRs - Brand guidelines we use - Information for contributing without code
1
3
117
SpecterWallet retweeted
🚨Warning: This is not only hitting us. Same hacking campaign is also standing up fake sites for: @fold_app @PhoenixWallet They then trick people into installing malware that hands the attacker remote control of the pc.
⚠️ Warning: A highly convincing FAKE Specter Desktop website is currently online. Do not download or install anything from it. The downloads contain malware. Only use official Specter sources.
5
9
17
2,003
They also created fake sites for other projects
🚨Warning: This is not only hitting us. Same hacking campaign is also standing up fake sites for: @fold_app @PhoenixWallet They then trick people into installing malware that hands the attacker remote control of the pc.
1
2
193
SpecterWallet retweeted
Thanks to the help of our awesome @SpecterWallet and @SpecterDIY Community, we found out very quickly that the scammers used @vercel to host their domain. So I reported them. Hope they will get shut down soon.
⚠️ Warning: A highly convincing FAKE Specter Desktop website is currently online. Do not download or install anything from it. The downloads contain malware. Only use official Specter sources.
1
4
337
SpecterWallet retweeted
Our Lead Specter Desktop Developer @k9ert analysed the FAKE-Specter Desktop Installer from the Clone Site. It does not install Specter Desktop. The download is a dropper. It requests admin rights behind a Microsoft-signed "Windows Command Processor" UAC prompt, briefly adds a Defender exclusion, silently installs an unattended ConnectWise ScreenConnect client with SYSTEM-level remote control, then opens a genuine signed DocuSign print driver so the install looks legitimate. You get a real DocuSign product. You do not get Specter. You do get a persistent backdoor hidden from Add/Remove Programs that survives Safe Mode. There is no wallet stealer in the file itself. The operator gets hands-on-keyboard access later and uses that channel afterwards. If you ran it: isolate the machine immediately. Do not try to clean it. Rebuild from known-good media. Rotate every credential used on that host. Treat wallet seeds, hot wallets, exchange keys and anything reachable from that PC as compromised. Move funds from a clean device only. Full report: gist.github.com/k9ert/724ac0… Official Specter Desktop only: specter.solutions/desktop/
⚠️ Warning: A highly convincing FAKE Specter Desktop website is currently online. Do not download or install anything from it. The downloads contain malware. Only use official Specter sources.
Made with AI
4
7
767
We have also received a report of a fraudulent email newsletter sent from this fake domain. It is currently unclear which email addresses they are targeting.
⚠️ Warning: A highly convincing FAKE Specter Desktop website is currently online. Do not download or install anything from it. The downloads contain malware. Only use official Specter sources.
2
5
15
2,308
If you are affected, please reach out to @Schnuartz so we can better understand who is being targeted and narrow down which groups are affected.
I'm currently trying to figure out which people have been affected by the fake emails so I can send out warnings and further narrow down the problem. If you've been affected, please message me on X or email me at my official Specter email address: 👉schnuartz@specter.solutions
1
4
135
SpecterWallet retweeted
I'm currently trying to figure out which people have been affected by the fake emails so I can send out warnings and further narrow down the problem. If you've been affected, please message me on X or email me at my official Specter email address: 👉schnuartz@specter.solutions
We have also received a report of a fraudulent email newsletter sent from this fake domain. It is currently unclear which email addresses they are targeting.
1
3
6
859
SpecterWallet retweeted
We found out that the fake Specter Desktop domain is only three days old
⚠️ Warning: A highly convincing FAKE Specter Desktop website is currently online. Do not download or install anything from it. The downloads contain malware. Only use official Specter sources.
1
3
740
⚠️ Warning: A highly convincing FAKE Specter Desktop website is currently online. Do not download or install anything from it. The downloads contain malware. Only use official Specter sources.
3
31
52
13,715
This is the only Real Specter Desktop Website: specter.solutions/desktop Thanks to @oren_z0 for reporting
2
8
434
The Coldcard entropy failure was a brutal stress test for self-custody. Singlesig got wrecked. Multisig held the line. Here’s why Specter Desktop users who ran proper multisig stayed safe 🧵
1
1
184
4/ Best practices that actually mattered in this incident: • Keep descriptors offline & private • Prefer mixed hardware vendors • Never reuse addresses • Quorum > any single manufacturer Specter was built for exactly this threat model.
1
27
5/ Bottom line for those who already lived through the waves: Hardware will fail. Firmware bugs will happen. The architecture that survives is multisig done properly. Specter Desktop has been the most accessible way to run that architecture for years.
29
SpecterWallet retweeted
If you're moving your Bitcoin into a complicated setup (e.g. multi-vendor multisig) that you don't have plans to touch for years, @SpecterWallet and @ElectrumWallet let you create pre-signed Timelock Recovery transactions that can move the Bitcoin to a simple single-vendor wallet. Can't figure out how to operate the multisig wallet you configured 5 years ago? Just broadcast the pre-signed transactions, and within 90 days (configurable) the Bitcoin moves to the simple wallet. More info: TimelockRecovery.com
Lots of people are changing how they store their bitcoin right now, whether that means switching hardware wallets or moving to a custodian. Whatever you choose, practice using it. Know how to secure your access, deposit, withdraw, spend, and recover your funds. The first time you really need to use your setup shouldn’t be during an emergency.
2
2
97