Trezor Impersonation Scams
Scammers impersonate Trezor with fake firmware update emails and phishing versions of Trezor Suite. Trezor will never send an unsolicited email asking you to enter your recovery seed on a website.
Last reviewed: 1 June 2026
Trezor hardware wallets store private keys offline, but scammers target the setup and update experience to intercept the seed phrase. Phishing campaigns mimic Trezor's emails and Suite software, while fake Trezor Suite apps circulate through unofficial channels with seed-harvesting code embedded.
The safety rule is absolute: your recovery seed should only ever be entered on the physical Trezor device screen during a factory-reset restore. Any software or website requesting it is malicious.
How scammers impersonate it
- Distributing fake Trezor Suite desktop apps that harvest the recovery seed on entry
- Sending emails claiming a firmware update is required and linking to a phishing site
- Creating fraudulent 'Trezor Suite' listings in app stores not affiliated with Trezor
- Impersonating Trezor support on Reddit and Telegram to request seed phrases
- Running ads for fake 'Trezor wallet migration' tools during genuine product launches
What the real organisation never does
- Send unsolicited emails asking you to confirm or enter your recovery seed
- Require a firmware update through any site other than the Trezor device itself
- Offer support via Telegram direct messages
- Request payment to unlock, update, or recover your Trezor
Common red flags
- Email urging a firmware update with a download link rather than through Trezor Suite
- Trezor Suite downloaded from any source other than trezor.io
- Any form — on-screen or physical — asking for your recovery seed
- Telegram DMs from accounts claiming to offer Trezor support
- Urgency framing: 'Your wallet will become inaccessible unless you update today'
Sanitized example messages
Illustrative, sanitized examples. Personal details are replaced with placeholders such as [phone number] and [fake link].
Email: 'Important Trezor Security Update: Download Trezor Suite [version] from [fake link] to protect your assets.'
Fake app prompt: 'Your Trezor requires re-pairing. Enter your 12/24-word recovery seed to continue.'
How to verify
- Download Trezor Suite only from trezor.io/trezor-suite
- Verify firmware updates only through the official Trezor Suite application connected to your device
- Remember: your seed is entered only on the Trezor device screen, never in any software
- Check trezor.io/support for any genuine security notices
What to do if you're targeted
- Do not enter your seed phrase — disconnect from the fake site or app immediately
- If seed was entered, move assets to a new wallet with a fresh seed phrase without delay
- Report malicious sites to Trezor at [email protected]
Frequently asked questions
Does Trezor Suite ever ask for my recovery seed?
No. Legitimate Trezor Suite only ever asks you to enter your recovery seed on the physical Trezor device screen during a device wipe and restore. Any software requesting the seed on your computer screen is malicious.