Phishing: Critical Vulnerability Notice

I’m concerned that I received this mail exactly at the moment I installed the Trezor Suite on a new computer. How come? Do the hackers now watch new installations? Seems a bit fishy to me.

Critical Vulnerability Notice

Dear Customer,

We are writing to inform you of a critical security vulnerability that requires your immediate action. This notice concerns the firmware on your Trezor hardware wallet and its interaction with Trezor Suite.

Our security team recently discovered that threat actors breached a Trezor Suite administrative server. During the breach, they exploited a previously unknown zero-day vulnerability in the Trezor firmware. The attack was targeted at users who had an active connection from their device to Trezor Suite during the incident window.

This exploit allowed for Remote Code Execution (RCE) on the affected devices. We have confirmed cases where users’ devices were compromised, potentially allowing attackers to extract sensitive information. You are receiving this email because your account was active during the at-risk period. Therefore, you must assume your device is vulnerable.

To protect your assets, it is absolutely crucial to act now. We have released an emergency firmware patch that closes this vulnerability. You must connect your device and follow the guided update process immediately.
[Proceed to Web Dashboard]
We take these matters with the utmost seriousness and sincerely apologize for this situation. Your security is our highest priority.

Sincerely,

4 Likes

I believe this is a scam. I just received the same notice and I haven’t accessed my wallet for quite some time. Also, true to form, these scams want you to click on their provided links, the email doesn’t match Trezors and I’m sure if the email was legit, it would direct you to login and deal with and security issue.

3 Likes

Same here. Take attention to odd domain and no secure http.

Proceed to Web Dashboard Button hides following link

(http://url8285.extend.com/ls/click?upn=u001.6ak-2B5Pj5qjuTOc....long string continues here)
3 Likes

I received the same suspicious email. Critical Vulnerability Notice

2 Likes

Got this email. Is it legit?

Dear Customer,

We are writing to inform you of a critical security vulnerability that requires your immediate action. This notice concerns the firmware on your Trezor hardware wallet and its interaction with Trezor Suite.

Our security team recently discovered that threat actors breached a Trezor Suite administrative server. During the breach, they exploited a previously unknown zero-day vulnerability in the Trezor firmware. The attack was targeted at users who had an active connection from their device to Trezor Suite during the incident window.

This exploit allowed for Remote Code Execution (RCE) on the affected devices. We have confirmed cases where users’ devices were compromised, potentially allowing attackers to extract sensitive information. You are receiving this email because your account was active during the at-risk period. Therefore, you must assume your device is vulnerable.

To protect your assets, it is absolutely crucial to act now. We have released an emergency firmware patch that closes this vulnerability. You must connect your device and follow the guided update process immediately.
Proceed to Web Dashboard
We take these matters with the utmost seriousness and sincerely apologize for this situation. Your security is our highest priority.

Sincerely,

The Trezor Security Team
Twitter YouTube Reddit

BlogSupportUnsubscribe

© 2025 Trezor by SatoshiLabs. All rights reserved.
SatoshiLabs s.r.o., Kundratka 2359/17a, 180 00 Praha 8, Czechia

1 Like

I got a fairly convincing phishing email this morning. it was sent from [email protected]
Here it is:

Critical Vulnerability Notice

Dear Customer,

We are writing to inform you of a critical security vulnerability that requires your immediate action. This notice concerns the firmware on your Trezor hardware wallet and its interaction with Trezor Suite.

Our security team recently discovered that threat actors breached a Trezor Suite administrative server. During the breach, they exploited a previously unknown zero-day vulnerability in the Trezor firmware. The attack was targeted at users who had an active connection from their device to Trezor Suite during the incident window.

This exploit allowed for Remote Code Execution (RCE) on the affected devices. We have confirmed cases where users’ devices were compromised, potentially allowing attackers to extract sensitive information. You are receiving this email because your account was active during the at-risk period. Therefore, you must assume your device is vulnerable.

To protect your assets, it is absolutely crucial to act now. We have released an emergency firmware patch that closes this vulnerability. You must connect your device and follow the guided update process immediately.
Proceed to Web Dashboard
We take these matters with the utmost seriousness and sincerely apologize for this situation. Your security is our highest priority.

Sincerely,

The Trezor Security Team

1 Like

Hello, @deirh @Pops @bjamsa @PWhizzle @taqsman @jDunn

Thank you for letting us know.

The email you received is a phishing attempt and was not sent by us. Please do not click any links or provide any information.

We appreciate you reporting it. Stay safe!

2 Likes

I received the same email, it’s definitely phishing. I also received a similar email last week & contacted Trevor customer service who said it was not a legitimate email from them. Delete it and remember never reveal your seed phrase to anyone.

1 Like

I received the same email that appears to be a scam yesterday… So my question is how do these scammers know that we bought trezor? How do they know we have used it? It looks like there really was some kind of breach by Trezor of who is using these cold strorage devices…

Hey support , I suggest you address this breach as I don’t trust that these scammers have a list of who is using a trezor along with their emails… There are lots of other storage wallets available so why trust a trezor if our contact info is being accessed and used to try and scam us …

1 Like

The usual answer is, they don’t.

They bought a list of “crypto wallet users” on some dark site and spray literally all of it.

People who don’t own a Trezor won’t go to the Trezor forum to complain, they’ll just delete it…

(how many “security incident” e-mails about products that you’re not using have you received in the last month? How about those that went straight to spam, because they don’t include a keyword that you interacted with in the past?)

… and people who just happened to connect the Trezor yesterday will get spooked and come here looking for answers.

This campaign is not targeted beyond using a list of e-mails associated with cryptocurrency. Everyone is getting it, including users who never actually bought a Trezor, and users of competitor products. It costs next to nothing to spam half the internet; most will get ignored, but some will bite.

(there was a breach of the Trezor mailing list a while back; nothing about this suggests that this is a new one)

2 Likes

Hi everyone,

I received a suspicious email about an issue with my trezor. Here is the email address: “Trezor [email protected]”. I’ve also attached the screenshots of that email her, so have a look. Could someone tell me if it’s a scam or really trezor. I tried to contact the support service on trezor website but when I click on “contact our support” there is nothing happening. I would love to be in touch with a team member from trezor to check that issue. If anyone got the same problem, please help me. Kind regards.!

Screenshot 2025-06-30 211148|690x322

I can’t agree, it is at least partially targeted, see
https://forum.trezor.io/t/phishing-email-received-on-my-email-address-that-only-trezor-is-aware-about/23778/2
the scammers used my unique email address that I used when buying trezor device, and never used/published anywhere else. They must have found it somewhere in your systems. Even on this forum I registered today, with different email address.

as I wrote at the end of my reply:

Think this should be sent to all your users?
Most would never go to this site.

We have notified about this phishing attempt on our socials.