I updated firmware and my funds were transfered to trenzor suite

there are basically 2 scenarios of what could have happened:

  1. Either some 3rd person used your Trezor physically for confirming the transaction

  2. Your private keys (represented by your recovery seed) were compromised and the attacker used them to sign the transaction. This is possible since you can recover your wallet including your private keys by performing a recovery with a compatible wallet.

1 Like

I am the only one that use the wallet. I did try to do a recovery in trenzor suite and it seems to have gotten corrupted.

  1. Is the btc address a trezor suite address?
  2. can they find it in their system and revert the transaction or transfer back?
  3. I don’t think i was compromised. All i did was install firmware and then tried to restore via trenzor suite with the 24 word seed when it seems to have failed then it would not connect to exodus telling me a website or program is in session and it could not pair with it anymore. It kept failing.

I am the only one that use the wallet. I did try to do a recovery in trenzor suite and it seems to have gotten corrupted.

  1. Is the btc address a trezor suite address?
  2. can they find it in their system and revert the transaction or transfer back?
  3. I don’t think i was compromised. All i did was install firmware and then tried to restore via trenzor suite with the 24 word seed when it seems to have failed then it would not connect to exodus telling me a website or program is in session and it could not pair with it anymore. It kept failing.
    Also my other accounts in exodus still have my crytpo when i restore on the same machine.
  1. It is not possible to say (unless it is other account in Trezor Suite)

  2. It is not possible to revert transactions

  3. First, go to settings in Suite, App, Reset app.

Then what about those other accounts? Do you see them in Suite?

  1. I mean if it is stored in trezor suite web then they can send me back since i believe i can prove the funds were sent without my knowledge.

If i reset app does it make a difference? I have done it a couple times with my seed but it says $0.00. I believe they were restored in trezor suite in some btc address since the funds have not moved and the wallet was created at the same time i was doing the restoraton etc. I havent heard from anyone in Trezor even though i created a ticket some hours ago.

The other accouns i see in suite but they have $0.00.

Nothing is stored in Suite, you are looking at the outgoing transaction from your own wallet, your money is gone to that address.

Resetting will fix the two wallets issue, you said you see other accounts ok in Exodus,

Its gone to that address. Can it still be in my trezor?

click + button in the accounts/upper left and add native segwit account, it it is not there then your keys have been compromised.

I have tried what you say and all have zero balance. All my savings gone. I can believe this happened. I am devastated. How can Trezor be compromised like that? I really hope this can be investigated by the company. Its a bad experience to loose crypto just like that. How comes i never lost the other crytpo in my exodus main account wallet when I restored. Its just the one in the Trezor transfered without my knowledge and instantly. Never thought I would get this from a hardware wallet.

Your Exodus paired with Trezro and Trezor Suite are the SAME wallet, you are just using different interface.

I do not understand what you mean by restoring main account in Exodus, you restored with what? Trezor Seed? If yes then you would see the same transaction.

Your Main exodus account is different then your Trezor account in Exodus.

Its all confusing. I tried to restore via trezor . io / start I don’t recall if i did manage to input my 24 seed because i was doing it wrong. Somehow I only figure it out hours later and thats when i noticed that right around the time i was upgrading the firmware is when I the transaction was sent to that address. If i recall i did it wrong and only entered 12 words instead of 24 and it was wrong since i was picking and counting down words from the drop down list instead of reading from the seed order i have written down. Anyhow seems my funds are gone now. I did submit a ticket via the chat here but so far no one has anwered. Exodus team is helping me investigate and I have provided them with malware scan which didnt find anything on laptop and they asked me what i have done. I would really like if someone can remote to my pc and guide me but the hard fact is funds are gone to another btc address which i have no control of.

I just saw a post that has the same thing that happend to me

https://forum.trezor.io/t/zero-balance-after-firmware-update/6671

this is how you recover 24 words on model one (Only via Suite or web version of Suite, or Exodus itself), if you did anything else you have visited phishing site.
Yes, there are some decoy words that you select from the list but otherwise Trezor tells you which word to write down (like write 2nd word, write 13th etc.)

You surely were’t just picking random stuff, it does not work like that you would not recover the wallet.

Also, installing FW is the first step not the last.

The post above is the same thing that happened to me.

yes, and the user clearly mentioned a website that is not Trezor, plus you do not need the seed for the update , so…everything points out that you visited phishing website and gave away your seed.

The same thing has happened to me. How is this possible? Has Trezor been hacked? Where have my funds suddenly gone? It saying they were transacted out to another btc account…

Im in the same position, did you get your money back?

No. I haven’t heard from Support yet.

I can’t see any Ticket ID here. Could you please post it again here, below?

Happened to notice there was this mailchimp phishing fake Trezor Suite email that happened recently. Maybe something similar happened here where a scammer version of the Trezor Suite was downloaded?

Won’t let me include a link to article. But search mailchimp trezor and you will find it.