Spot the Scam · Phishing
Scam or legit?
This email lands in your inbox the morning after a big crypto headline.
Inbox
ACTION REQUIRED: Critical firmware vulnerability (CVE-2026-1182)Vaultly Security <security@vaultly-firmware-update.example>A critical vulnerability affects all Vaultly devices shipped before 2026.Download the patched Vaultly Manager below. During setup you will be asked to re-enter your recovery phrase to migrate your funds safely.Devices not updated within 24 hours may lose access to assets.Download patched Vaultly Managerhttps://vaultly-firmware-update.example/download
How to spot this (Urgent firmware update email)
- The sender domain is not the maker's domain — it just contains the brand name.
- Firmware updates never need your recovery phrase. Typing it into any app or website hands it over.
- Never install wallet software from an email link. Open the official app you already have.
Remember: Updates come through the official app you already installed — and no update ever needs your recovery phrase.
All brands in these scenarios are fictional. Scenarios are based on common scam patterns.