Change address explained

I had purchased Trezor One on marketplace and since I got it not from official shop, I extra cautiously made sure packaging and seal is fine, then I installed firmware (as shown on thezor display) with suite from trezor-io-start and set up a wallet from first attempt and used it for a month. It is out of the question that seed phrase was not seen by anyone.
Wallet worked just fine until I noticed outgoing tx from my wallet.
https://etherscan.io/tx/0x044455690e5194285f60a60e263566c4348096e5ce78e1d863e1950c60e1877f
interesting detail that gas limit set to 25000, instead of 21000, leaving me with $2 kek. Then I found that my BTC was also lost:

Is it possible that seller pre-generated seed and when I set trezor up I got keys that hacker already knew?

Some additional info
Time difference of ~5 min between two txs does not help to conclude which address was drained first.
At the time of attack (and before) trezor was with me.
Also while inspecting package after the hack I noticed that the box cannot be opened through the top without tearing paper up (glue is strong), but when I opened it for the first time from bottom, it opened easy without damage to paper (glue was apparently weak). Besides, is I said before, holographic seals seemed untouched.

Finally, I’d like to ask, how was I hacked?

I don’t know how you were hacked.
But I think you shouldn’t do what I did when I got the equipment.

  1. After installing the firmware, I create a wallet and record the seed phrase
  2. I wip trezor, recreate the wallet, record the new seed phrase
  3. I wip trezor again, recreate the wallet, record the seed phrase
  4. wip trezor, use the third seed phrase to restore the wallet.
    Three sets of seed phrase words are produced each time. I feel that it should not be the kind of dangerous equipment that has been assigned seed phrase words.

I got the same problem on 10/28/2021.
my BTC is gone
Hope the manufacture can notice of that and take some security action to stop the incident going on for losing confident to use Trezor to storage the coins

14th i was hacked and all my funds were stolen too. This is my article:

I don`t know how it can be possible, but my wallet was original, and used only month and a half. My mnemonicPhrase was hardly stored in hidden place.

Ticket 158319 - 12/16/2022.

On December 9 I did a transfer of 0.0018579 BTC from my Trezor to a DEX BISQ Wallet, I have this transaction registered in my Trezor Suite. By the way, I always use the Suite.

The balance in my Trezor shows, until today, the right BTC quantity, however, I had 0.16 BTC from one of my wallets in the Trezor transferred for an unknown wallet, in the same block of the Bisq transfer described above. The unknown transaction was made WITHOUT MY ACKNOWLEDGMENT. Besides, I don’t have this transaction registered in my Trezor.

Details:

  1. I bought my Trezor T on Amazon on May 21, 2021, from SatoshiLabs - Order 114-8238880-4664208
  2. I backup my seeds on paper ONLY and it be safe in my safe box.
  3. I only use Trezor SUITE on my Macbook.

I ask for @Satoshilabs. How this is possible? I wasn’t asked to make the Hack transaction in my Trezor. I still with the correct balance in my Trezor. I don’t have the hack transaction on my Trezor Suite and it’s just impossible for a hacker had been accessed to my seeds on paper.

I need to know what happened with the security hard wallet.

@wteixeira1969 sorry to hear that…

Comunnity support wil reply soon.

The only thing I can say is either:

Seed was exposed?

Someone had access to Trezordevice?

Transaction ID can help at least to track the funds.

Good Luck :four_leaf_clover:

It’s called a “change address” and that other address is, weirdly enough, also part of your Trezor account.
I’d love to link you to a learning resource, but can’t find one right now – Trezor’s wiki page about change addresses is currently broken.
Maybe some other forum user can help out?

1 Like

@wteixeira1969 This is a “Change Address” situation, which means in bitcoin terminology that bitcoins were sent but not completely spent from the specific address.

Let’s demonstrate it in an example, you visit a store and want to buy some goods for 2 EUR. In your wallet is only a 5 Euro note, so you give the seller the 5 Euro note and he will return you 3 Euros in some coins (change). It is similar with Bitcoin.

The address is not visible in Trezor wallet because we want to keep the simplicity of our product, but the balance is correct.

1 Like

Hi.

My seeds is in my safe box on paper. anyone had accessed my trezor. The unknown address who receive my BTC is not in trezor. I not confirm the transaction in my trezor.

Unfortunately, the other possibility is my trezor was hacked! and for me is a very deception because I bought a hardware walet to avoid this one.

I’ll send my case for some YouTubers for alert others about this security fail on trezor.

please, read the posts above, your trezor was not hacked, that is how BTC transactions work. Or at least provide transaction ID so we can confirm it.

1 Like

Heyyy @wteixeira1969

Please see forgi’s Post above

As he has identified the issue and explained…

:+1:

I read Forgi, but I don’t have the supported transferred address in my Trezor so.

Follow the transaction ID. Please, help me to change ny mind.

2ed1d65e057615d7e4c1a53434bab79132def4fc695656bb859f3d6ead105125

But, I can’t open the TX ID address in my browser.

yes, standard transaction with change address not a hack, you confirmed that your balance is correct. You cannot see the address because it is an advanced thing.

You can use coincontrol if you want to see it or some advanced wallet like electrum: https://trezor.io/learn/a/coin-control-in-trezor-suite

OK but, How can I follow my portfolio if I can have the address in my wallet? I use CoinStats. I can put the new address in CoinStats but this is not right if I can see the address in Trezor.

your total balance is always correct. It is combined value of all your addresses including UTXOs.
It does not show the wrong value.

If yo use some tool to track it then I suggest tracking it with your Xpub.

1 Like

@wteixeira1969

If you want to learn more please check this topic

It will help understand better…

Good luck

It works Jorgi.

I’m crying !!!

Thanks, man. I learned something new today.

Thanks for all the support guys.

2 Likes

@rimaS I will. Thanks, man. I appreciated.

1 Like

Why shouldn’t we do that? I think that is a great idea