Got hacked and lost 14kusd from trezor wallet with false popup screen when plugged in wallet

So I let my guard down when I plugged in my trezor T and a screen popped up saying I needed to verify my seed phrase. I’ve got all sorts off protection on this pc connected to. Had had a couple connection issues recently. Thought fair enough wanting to verify, so plugged in seed to screen - which by the way had right logo and colors and even asked me to be very careful with being alone in room etc etc when entering seed phrase etc. Entered seed phrase nothing happened. reset everything and checked when got in to wallet and all was ok. A couple days later same thing happens again. This time also nothing happens after entering seed phrase. Resent everything and managed to get in to wallet. This time all my btc and eth had been transferred to 10 separate addresses. I let my guard down thinking I’m on my pc and interacting directly with my wallet. Had just updated my trezor suite from trezor a couple days before. Lost approx 14kUSD which is 23kNZD. So enough to hurt. Have told a couple of close friends of my, one of who is a security internet consultant. Am scratching my head as to how the person got in. I was in IT for 25 years. Baffles me how they did it. It was obviously the fake verification screen that did it, but how they planted it who knows. Have NZ Cyber Chrimes unit on it.

Hi @Dan888

First, I’m so sorry this happened to you. Reading your post, it’s clear how careful you normally are, and how convincing these phishing scams have become. You’re definitely not alone — these types of attacks are becoming increasingly sophisticated, especially when they manage to replicate the Trezor Suite interface.

To help clarify what happened: Trezor Suite will never ask you to enter your your wallet backup (aka seed phrase) on your computer screen — ever. The only time you should ever enter your wallet backup is directly into your Trezor device, and even then, only when you’re intentionally restoring a wallet yourself or checking your backup. If you’re ever prompted to type your wallet backup into your PC or phone, it’s a red flag — it’s a scam.

What likely happened in your case is that a fake website, masquerading as an official Trezor resource, tricked you into entering your wallet backup on a web form or app that looked legitimate. Once the attacker has your backup, they can restore your wallet and access your funds from anywhere in the world.

Going forward:

  • Never enter your wallet backup on any website, app, or into your computer — only into the Trezor device screen when you personally initiate a restore.
  • Double-check all URLs. Our only official website is trezor.io.

Again, I’m truly sorry for your loss. Thank you for sharing your experience — it may help prevent someone else from going through the same thing.

Stay safe, and don’t hesitate to reach out if you need help checking links or verifying anything in the future.

1 Like

Uff me pasa a mi esto y creo que me da un colapso, soy nueva, hace poco compre Trezor Safe 5 y solo tengo un poco de XRP compre en Kraken 500 euros de Ethereum los quise pasar a Trezor ya que me dijeron que los exchanges no eran seguros, y por ser nueva en ese ecosistema pensaba que solo existia un Ethereum, en Trezo sale Ethereum Classic y Ethereum, yo crei que el Clasico era el Ethereum Clasic y al hacer la transaccion no me llegaron a trezor, y no se como recuperarlos, se que estan en la blockchain de Ethereum, pero no pude recuperarlos, porque no se como , asi que estoy intentando que alguien de soporte de trezor me pueda ayudar. Siento mucho de verdad lo leido, y no entiendo como pueden haber personas asi. Un gran abrazo

@Montse The issue you are describing is different and should be fixable :smile: Please see our video about How to recover ETH sent to ETC address.

Here’s an outline of how to complete this process:

Needed tool: MyEtherWallet
General information on how to connect Trezor with MEW can be found at https://trezor.io/learn/a/myetherwallet-and-trezor

  1. It’s necessary to set the Safety checks from Strict to Prompt in Trezor Suite to perform these next steps. Keep in mind that Safety checks are reset to default after the Trezor device is reconnected - it is important not to disconnect Trezor after the edit of Safety checks and before the funds are sent to the correct address.

This can be done in the “Settings” under the “Device tab” where Safety checks can be edited:

  1. Go to Trezor Suite and select Ethereum. Go to Receive tab and click on Show full address. Copy that address, verify it on Trezor’s device display.
  2. To import Trezor’s public keys, connect Trezor device to MyEtherWallet and pair it with Trezor.
  3. As a network, keep using ETH.
  4. As a derivation path, choose Ethereum Classic (m/44’/61’/0’/0) - the address with ETH is on this derivation path.
  5. After accessing the address, verify that you are still using the Ethereum network in the right corner - you can always change the network there (right now you are on the Ethereum network, but with derivation path m/44’/61’/0’/0 that is being used for Ethereum Classic).
  6. Send the ETH tokens to the address from step 2 (from the address you have got from Trezor Suite).

Let me know if you have any further questions. You might also want to create a ticket via our Chatbot Hal if you wish to speak with a technical support agent.