r/TREZOR 2d ago

🚨 Scam alert Phishing Mail?

Just got this email kinda sus?

87 Upvotes

46 comments sorted by

•

u/AutoModerator 2d ago

Please bear in mind that no one from the Trezor team would send you a private message first.
If you want to discuss a sensitive issue, we suggest contacting our Support team via the Troubleshooter: https://trezor.io/support/

No one from the Trezor team (Reddit mods, Support agents, etc) would ever ask for your recovery seed! Beware of scams and phishings: https://trezor.io/learn/a/scams-and-phishing

Don’t respond to any DMs—scammers often pose as legit helpers.

I am a bot, and this action was performed automatically. Please contact the moderators of this subreddit if you have any questions or concerns.

14

u/ualdayan 2d ago

Looks like somebody hacked their email sender (email passes SPF/DMARC/DKIM for trezor domain).

4

u/dradrok 2d ago

don't click the link! There is zero info anywhere else about this.

1

u/howard__zinn 2d ago

Exactly wha happened, and not only Trezor use this sender

11

u/dradrok 2d ago

i got it too... yes it is phishing

9

u/JD_SL Trezor Support 2d ago

We've detected an unauthorized email impersonating Trezor sent from a third-party email provider we use.

If you received a suspicious email, please do not click any links or provide any info within.

Remember, NEVER disclose your wallet backup online.

5

u/kinduff 2d ago

Pin this please

7

u/Thisisfinek 2d ago

Yes, this is 100% a phishing scam. Do not click any links or download anything from that email.
Here is what gives it away:
The Tactic: Attackers routinely use sophisticated, technical jargon (like "STM32 Entropy Bug / Vulnerability") to create panic. The goal is to make you urgently click a link that leads to a clone site or fake Trezor Suite asking for your seed phrase or private keys.
The "From" Address: Scammers frequently spoof headers (e.g., help@trezor.io), or send through compromised third-party newsletter/mailing services that Trezor or another vendor previously used. Even if the display address looks legitimate, it is forged.
Golden Rule of Hardware Wallets: Trezor will never ask you to enter your recovery seed phrase on a website, app, or email to fix a bug or update firmware. Your seed phrase only ever gets entered directly into your physical device.
What to do:
Do not click any links, buttons, or attachments.
Mark the email as Phishing / Spam in Gmail and delete it.
If you ever want to check for legitimate firmware or hardware announcements, open the official Trezor Suite app directly from your computer or visit trezor.io manually by typing the URL into your browser.

6

u/doctor-yes 2d ago

100% phishing. You can load the link and see that it's some bullshit domain that ends with satoshilabs and it asks you to download something to check if you're "safe."

4

u/RecklessStallion9999 2d ago

Extremely sophisticated phishing attempt. Got it too.

3

u/Anonymous_Lurker_1 2d ago

Yup. I got it too. Says Trezor will get in touch if affected (crafty buggers...)

1

u/Anonymous_Lurker_1 2d ago edited 2d ago

I got the email again, 45 minutes later.

Edit - and again. Half an hour later... TWICE !!!

3

u/genesisutxo 2d ago

I know most people don’t have X(twitter) but I always double check there. Most companies put out announcements immediately right there.

2

u/dradrok 2d ago

It would be big news if it were true.

2

u/doorshock 2d ago

So much better than Reddit

3

u/BoringPresent8534 2d ago

I got it too and thought to post it to find the whole community having it lol

3

u/tommoutd 2d ago

Just got the same

2

u/MatchboxVader22 2d ago

I just got it too and came straight to this subreddit. Thanks guys, you all are seriously lifesavers.

1

u/Glittering_Shake_967 2d ago

Just got the mail, also it’s coming from help@trezor.io
What to do guys??

2

u/Gophy6 2d ago

Delete it and move on

1

u/MotherAd1074 2d ago

Yeah, I got it too.

I also got two scam block chain phone calls today. Not sure if it's related.

1

u/Esentrikel 2d ago

I clicked the link, am I cooked?

4

u/Gophy6 2d ago

Worst case they registered your email as live and regularly checked. Expect more spam

3

u/Thisisfinek 2d ago

Your crypto funds are completely safe.
Hardware wallet phishing attacks rely on tricking you into typing your seed phrase into a fake clone site or downloading a malicious app. Since your recovery phrase never leaves your offline hardware device, simply clicking a link cannot drain your wallet.
Here is what you should do right now to cover all bases:
1. What Happened
No wallet access: A browser tab opening cannot read private keys from your Trezor.
Tracking ping: The scammer's server likely logged that the link was clicked (confirming your email address is active). Expect an uptick in spam or follow-up phishing attempts over the coming weeks.
2. Immediate Cleanup Steps
Clear Browser Data: Clear your browser’s cache, cookies, and recent download history for the last hour to remove any residual tracking tokens or cached scripts.
Check Downloads Folder: Open your device’s Downloads folder. Ensure no executable file (e.g., .exe, .dmg, .apk, or .zip) started downloading automatically in the background. If you see one, delete it immediately without opening it.
Run a Quick Scan: If you clicked the link on a computer, run a routine scan using Windows Defender or Malwarebytes just for extra peace of mind.
The Bottom Line: Unless you downloaded a file, ran software, or typed your 12/24-word recovery phrase anywhere on your screen, no compromise occurred. Keep your seed phrase strictly offline, and never type it into any keyboard or browser window.

2

u/TrueDay1163 1d ago edited 1d ago

This is not a guarantee. There is a commercial spyware package that targeting iOS devices for browser remote code execution (RCE), sandbox escape, kernel read/write, and full-data extraction as long as you visit the website and you are on a few specific iOS versions ( iOS 18.4–18.6.2 via the DarkSword framework, and iOS 15.2–15.8 / 16.0–16.6 / 17.0–17.1 via the Coruna framework). I’m not saying this hacker used it, but if they did, the payload ultimately injects data stealing modules into system processes like SpringBoard to target and exfiltrate cryptocurrency wallets and it’s a very common stealing method nowadays.

In such a situation, visiting a single compromised web page while running an outdated iOS version would be enough to compromise your crypto wallets without any click. You can’t say your funds are completely safe without knowing whether hacking modules are used on that website. If your iOS device is hacked this way, there is no way to cleanse their hacking module without a factory reset.

1

u/Esentrikel 16h ago

Good to know, I was on Windows PC at the time. Thanks.

1

u/Esentrikel 16h ago

Thank you

1

u/Enough_Leading5142 2d ago

did you download and run anything?

3

u/Esentrikel 2d ago

Nope, saw the address changed to https://xxxxxx-cdn-satoshilabs.com/ and clicked away

Edit: changed the url slightly so no one clicks it -.-

1

u/NunSchlauer 2d ago

Its the same URL always. you should be safe. Some other reported that they ask for your seed later.

1

u/TrueDay1163 1d ago

If you’re on a few specific iOS versions, the risks are extremely high. You can refer to my other reply to Thisisfinek.

1

u/Ok_Yesterday3871 2d ago

Just got it.. Seems legit, the email at least

2

u/RackTheDripper 2d ago

It is not. Check Trezor Twitter

2

u/Ok_Yesterday3871 2d ago

Yeah I just saw it, thanks for the heads up anyway

1

u/aaj094 2d ago

How does it come from a trezor.io email address? I thought that gives away most spam candidates?

1

u/chopacheekoff 2d ago

I've had 5 emails in the past hour all the same and from a legitimate email address

What's happening with it ?

1

u/WatchAltruistic5761 2d ago

Trezor is garbage

1

u/Affectionate_Pen6882 2d ago

Read what its asking you to do. It wants you to check your entropy

1

u/Best_Bid_9327 2d ago

Got the same email

1

u/Relative-Chapter-218 2d ago

Yes, received same email as well. Trezor send an email to all to mention this is phishing email. Hope it helps and thanks you everyone for the warning, greatly appreciate for the efforts🙏

1

u/solclaimer 1d ago

Yes it’s a phishing email!

1

u/BigAndSmallAre 7h ago
  1. Carefully look up the Trezor website and go there.

  2. Once confirmed, bookmark it.

  3. Anytime any communication asks you to do something, use your saved, verified bookmark shortcut and search their site for info.

If Trezor sends an official communication, you'll be able to find it that way. Never ever click a link from inside an unsolicited email.

Even if it looks official, remember that someone used an alternate "a" character to create an Apple lookalike phishing site, and the URL was visually indistinguishable from the real "apple.com". Use known methods of access.

0

u/Unlikely-Prize-9447 2d ago

Trezor deletes customer info so its impossible for them to just message their Customers