Hi All,
A month ago I purchased a Safe 5 BTC-Only & a regular Safe 3. I set them all up and have moved all my funds to them. Yet my paranoia still persists that one day all the funds will be magically gone, as I’ve heard horror stories of fake trezor devices that came from Russia a few years ago and another story of someone’s Ledger Nano X being completely drained even AFTER it passed a verification genuine check within Ledger Live. I know these two things are outliers as the fake Trezors that came from Russia were not authorized sellers and the same thing with the Ledger coming from an unauthorized seller in Thailand, but my paranoia still persists.
Some further details regarding all the security measures and redundancies I’ve taken are listed below:
-
Brand new laptop with Linux installed that has ONLY ever visited official Trezor site to download suite.
-
All packaging on my Trezor was untampered with, holographic seals, plastics, box rip-tag intact.
-
Ordered directly from official Trezor site.
-
Nobody knows I own crypto or have these devices, I live alone.
-
I use passphrase on both devices and seeds are stored securely and separately from the passphrases.
-
Passphrases and seeds were only ever written down on paper & metal and away from any cameras/webcams and then immediately secured.
-
I have verified the Trezor Suite signatures in the programming before using the Suite via this guide titled “Download & verify Trezor Suite” on the official Trezor Site.
-
Both my Safe 5 and 3 have passed the genuine checks within Suite and I always keep the firmware up-to-date and only download the firmware directly from within the Suite application.
My main concerns below that I’m hoping someone more knowledge/a developer could answer for me to put me more at ease is:
1. Is there anyway a fake Trezor Safe 5 or 3 could still pass the genuine security check within Trezor Suite?
2. I am 99.9% sure when i first plugged in my Trezors there was no firmware installed, and I was only prompted that firmware was installed already after I performed my first initial device setup, wipe and reset on it to confirm my seed phrases were correct. Is there anyway to be for certain that the firmware im using is genuine and not compromised? This is just my paranoia i guess… for reference my Trezors are both currently running firmware 2.9.4 as of today, Jan 2nd 2026.
3. My funds have been on these Trezors for a little over a month now, so I am assuming I have done everything safely and correctly, and that my devices are not compromised because if they were compromised my funds would’ve been drained by now?
I know this seems like a very paranoid post, and i’ll admit it is but I am just looking for the Trezor team to put my mind at ease here as it is my worst fear of waking up to my wallet being drained.
Thank you all very much for the help here.