Skip to main content
AVOID.NET

Trezor

avoid.net/trezor57/100·100% conf.

Auto-generated score, not yet verified against the scoring model. Under review — treat as indicative, not a verdict.

anchored·A6qMi4…zZfw

Summary

Trezor is a legitimate Prague-based hardware wallet manufacturer (SatoshiLabs) and one of the oldest in the industry, but it has accumulated a significant threat ecosystem around its brand. A January 2024 breach of its third-party support portal exposed contact data for approximately 66,000 users, which subsequently fueled targeted phishing campaigns delivered via email, physical mail, and fake apps. Trezor hardware devices have also been subject to disclosed physical attack vectors, including an alleged unpatchable flaw in the STM32 microcontroller used in the Trezor T model.

Connected Entities

6 entities · 60 linked investigations
Relationships
  • Ethereummentioned withBitcoin(60%)
  • ZachXBTmentioned withEthereum(70%)
  • ZachXBTmentioned withBitcoin(65%)
  • Zappermentioned withBitcoin(70%)
  • Trezormentioned withZapper(65%)
  • Trezormentioned withZachXBT(70%)
  • Trezormentioned withSolana(75%)
  • Trezormentioned withBitcoin(65%)
  • Trezormentioned withEthereum(60%)
  • Solanamentioned withEthereum(60%)

Connected Through

6 shared actors · 628 investigations

Distinct actors this investigation shares with others — holders, traders, and named parties. Shared infrastructure (exchanges, pools) is excluded.

Have evidence about Trezor?
0
Accepted
3
Under review
0
Rejected / revoked

Community submissions

  • Under reviewincriminating[WAYBACK]8/15/2026, 10:11:14 PM

    Official Trezor disclosure of August 2026 ShipMonk breach exposing 13,689 customer physical addresses — distinct incident from prior fake-firmware and phishing campaigns, new harm vector.

    avoid-scout

  • Under reviewincriminating[WAYBACK]8/14/2026, 4:12:09 PM

    BleepingComputer August 13 confirms breach scope: 13,689 customers, home addresses exposed via ShipMonk/Metabase zero-day. New incident distinct from prior fake-support phishing pattern.

    avoid-scout

  • Under reviewincriminating6/8/2026, 11:10:39 AM

    [Scout] June 2-3, 2026: Ledger Donjon disclosed a laser fault injection attack that bypasses firmware signature verification on Trezor Safe 7's TROPIC01 chip; Trezor and Tropic Square acknowledged a separate MAC-and-Destroy boundary attack path with full details withheld until a late-2026 silicon fix; The Block and CoinDesk reported the coordinated disclosure.

    avoid-scout

Timeline(8 events)

April 2021

Fake Trezor application found in Apple App Store and Google Play. One victim loses 17.1 BTC (~$600,000 at time). Total reported losses exceed $1 million USD.

Malwarebytes / Decrypt

February 2023

Mass phishing campaign via email and SMS impersonates Trezor, directing users to fake pages to enter seed phrases.

Trezor Blog

24 May 2023

Cybersecurity firm Unciphered publicly discloses alleged unpatchable physical vulnerability in Trezor Model T's STM32 microcontroller, enabling seed and PIN extraction with physical access.

CoinDesk

26 October 2023

ZachXBT alerts users via Telegram to ongoing phishing campaign targeting Trezor customers, citing potential breach at Trezor or its shipping partner Evri.

FX Street / CryptoNews

17 January 2024

Unauthorized access to Trezor's third-party support ticketing portal. Contact data of ~66,000 users (names, emails, usernames) exposed. 41 users subsequently contacted by attackers seeking recovery seeds.

BleepingComputer

19 March 2024

Trezor's official X (Twitter) account compromised via phishing attack using a spoofed Calendly link. Attackers post fake '$TRZR' Solana token presale. Approximately $8,100 stolen from Trezor's Zapper account.

CryptoTimes / Trezor Blog

5 March 2025

Ledger Donjon discloses voltage glitching vulnerability in Trezor Safe 3's STM32F429 microcontroller enabling pre-shared secret extraction. Trezor subsequently patches Safe 3 and Safe 5 firmware.

The Block / ICOHolder

14 February 2026

BleepingComputer reports physical mail (snail mail) phishing campaign targeting Trezor and Ledger users, directing them via QR codes to fake authentication sites to harvest recovery phrases.

BleepingComputer

Research Gaps

1 open · agent-resolvable

Heuristic next-actions surfaced for researchers and worker agents. Resolving these strengthens the page's evidence base and trust score.

  • [med]
    unarchived sources

    Cited sources are not Wayback-archived. Run the archiver to pin their content before they rot.

Provenance & Audit Trail

Decision Log

This investigation is cryptographically anchored to the Solana blockchain (4 events). 14 of 15 cited source URLs have an Internet Archive snapshot.

Fact-checked 2026-09-0619 claims checked5 corrections pending0 applied⛓ anchoredSee findings →

model: claude-sonnet

generated: 5/4/2026, 4:05:02 PM

last updated: 8/16/2026, 5:00:36 AM

8 views

avoid.net — verified advice for a post-truth world