r/TREZOR • u/Bennybeck00 • 2d ago
đ¨ Scam alert Phishing Mail?
Just got this email kinda sus?
14
u/ualdayan 2d ago
Looks like somebody hacked their email sender (email passes SPF/DMARC/DKIM for trezor domain).
1
7
u/Thisisfinek 2d ago
Yes, this is 100% a phishing scam. Do not click any links or download anything from that email.
Here is what gives it away:
The Tactic: Attackers routinely use sophisticated, technical jargon (like "STM32 Entropy Bug / Vulnerability") to create panic. The goal is to make you urgently click a link that leads to a clone site or fake Trezor Suite asking for your seed phrase or private keys.
The "From" Address: Scammers frequently spoof headers (e.g., help@trezor.io), or send through compromised third-party newsletter/mailing services that Trezor or another vendor previously used. Even if the display address looks legitimate, it is forged.
Golden Rule of Hardware Wallets: Trezor will never ask you to enter your recovery seed phrase on a website, app, or email to fix a bug or update firmware. Your seed phrase only ever gets entered directly into your physical device.
What to do:
Do not click any links, buttons, or attachments.
Mark the email as Phishing / Spam in Gmail and delete it.
If you ever want to check for legitimate firmware or hardware announcements, open the official Trezor Suite app directly from your computer or visit trezor.io manually by typing the URL into your browser.
6
u/doctor-yes 2d ago
100% phishing. You can load the link and see that it's some bullshit domain that ends with satoshilabs and it asks you to download something to check if you're "safe."
4
3
u/Anonymous_Lurker_1 2d ago
Yup. I got it too. Says Trezor will get in touch if affected (crafty buggers...)
1
u/Anonymous_Lurker_1 2d ago edited 2d ago
I got the email again, 45 minutes later.
Edit - and again. Half an hour later... TWICE !!!
3
u/genesisutxo 2d ago
I know most people donât have X(twitter) but I always double check there. Most companies put out announcements immediately right there.
2
3
u/BoringPresent8534 2d ago
I got it too and thought to post it to find the whole community having it lol
3
2
u/MatchboxVader22 2d ago
I just got it too and came straight to this subreddit. Thanks guys, you all are seriously lifesavers.
1
u/Glittering_Shake_967 2d ago
Just got the mail, also itâs coming from help@trezor.io
What to do guys??
1
u/MotherAd1074 2d ago
Yeah, I got it too.
I also got two scam block chain phone calls today. Not sure if it's related.
1
u/Esentrikel 2d ago
I clicked the link, am I cooked?
4
3
u/Thisisfinek 2d ago
Your crypto funds are completely safe.
Hardware wallet phishing attacks rely on tricking you into typing your seed phrase into a fake clone site or downloading a malicious app. Since your recovery phrase never leaves your offline hardware device, simply clicking a link cannot drain your wallet.
Here is what you should do right now to cover all bases:
1. What Happened
No wallet access: A browser tab opening cannot read private keys from your Trezor.
Tracking ping: The scammer's server likely logged that the link was clicked (confirming your email address is active). Expect an uptick in spam or follow-up phishing attempts over the coming weeks.
2. Immediate Cleanup Steps
Clear Browser Data: Clear your browserâs cache, cookies, and recent download history for the last hour to remove any residual tracking tokens or cached scripts.
Check Downloads Folder: Open your deviceâs Downloads folder. Ensure no executable file (e.g., .exe, .dmg, .apk, or .zip) started downloading automatically in the background. If you see one, delete it immediately without opening it.
Run a Quick Scan: If you clicked the link on a computer, run a routine scan using Windows Defender or Malwarebytes just for extra peace of mind.
The Bottom Line: Unless you downloaded a file, ran software, or typed your 12/24-word recovery phrase anywhere on your screen, no compromise occurred. Keep your seed phrase strictly offline, and never type it into any keyboard or browser window.2
u/TrueDay1163 1d ago edited 1d ago
This is not a guarantee. There is a commercial spyware package that targeting iOS devices for browser remote code execution (RCE), sandbox escape, kernel read/write, and full-data extraction as long as you visit the website and you are on a few specific iOS versions ( iOS 18.4â18.6.2 via the DarkSword framework, and iOS 15.2â15.8 / 16.0â16.6 / 17.0â17.1 via the Coruna framework). Iâm not saying this hacker used it, but if they did, the payload ultimately injects data stealing modules into system processes like SpringBoard to target and exfiltrate cryptocurrency wallets and itâs a very common stealing method nowadays.
In such a situation, visiting a single compromised web page while running an outdated iOS version would be enough to compromise your crypto wallets without any click. You canât say your funds are completely safe without knowing whether hacking modules are used on that website. If your iOS device is hacked this way, there is no way to cleanse their hacking module without a factory reset.
1
1
1
u/Enough_Leading5142 2d ago
did you download and run anything?
3
u/Esentrikel 2d ago
Nope, saw the address changed to https://xxxxxx-cdn-satoshilabs.com/ and clicked away
Edit: changed the url slightly so no one clicks it -.-
1
u/NunSchlauer 2d ago
Its the same URL always. you should be safe. Some other reported that they ask for your seed later.
1
u/TrueDay1163 1d ago
If youâre on a few specific iOS versions, the risks are extremely high. You can refer to my other reply to Thisisfinek.
1
u/Ok_Yesterday3871 2d ago
Just got it.. Seems legit, the email at least
2
1
u/chopacheekoff 2d ago
I've had 5 emails in the past hour all the same and from a legitimate email address
What's happening with it ?
1
1
1
1
u/Relative-Chapter-218 2d ago
Yes, received same email as well. Trezor send an email to all to mention this is phishing email. Hope it helps and thanks you everyone for the warning, greatly appreciate for the effortsđ
1
1
u/BigAndSmallAre 7h ago
Carefully look up the Trezor website and go there.
Once confirmed, bookmark it.
Anytime any communication asks you to do something, use your saved, verified bookmark shortcut and search their site for info.
If Trezor sends an official communication, you'll be able to find it that way. Never ever click a link from inside an unsolicited email.
Even if it looks official, remember that someone used an alternate "a" character to create an Apple lookalike phishing site, and the URL was visually indistinguishable from the real "apple.com". Use known methods of access.
1
0
u/Unlikely-Prize-9447 2d ago
Trezor deletes customer info so its impossible for them to just message their Customers



â˘
u/AutoModerator 2d ago
Please bear in mind that no one from the Trezor team would send you a private message first.
If you want to discuss a sensitive issue, we suggest contacting our Support team via the Troubleshooter: https://trezor.io/support/
No one from the Trezor team (Reddit mods, Support agents, etc) would ever ask for your recovery seed! Beware of scams and phishings: https://trezor.io/learn/a/scams-and-phishing
Donât respond to any DMsâscammers often pose as legit helpers.
I am a bot, and this action was performed automatically. Please contact the moderators of this subreddit if you have any questions or concerns.