Skip to main content
AVOID.NET
Trezorreviewed 2026-09-06 · 19 claims checked

Fact-check findings

What an automated fact-checker found when it re-read Trezor against the sources the page cites. Only the most recent review is shown.

Read this first

These findings are produced by an automated reviewer, and its results vary between runs: the same page, checked three times on the same day, came back with 15%, 20% and 34% of its claims disputed, mostly because each run extracted a different number of claims. Treat what follows as leads, not rulings.

“Disputed” means the reviewer could not reconcile the claim with the evidence it cited. It does not mean the claim is false. “Unverifiable” means no reachable source settled it either way.

Nothing here changes the page on its own. A proposed correction is applied only after a human moderator approves it; until then the page reads as it did when reviewed.

disputed 5partially supported 4confirmed 105 corrections pending · 0 applied

disputed

5 claims

The reviewer could not reconcile the claim with the evidence it cited. This is a lead, not a ruling that the claim is false.

  1. #2[disputed][awaiting moderator]in the summary
    A January 2024 breach of its third-party support portal exposed contact data for approximately 66,000 users, which subsequently fueled targeted phishing campaigns delivered via email, physical mail, and fake apps.
    reviewerA January 2024 breach of Trezor's third-party support portal exposed contact data for approximately 66,000 users, which subsequently fueled targeted phishing campaigns delivered via email, physical mail, and fake apps.The summary implies the 2024 breach caused/fueled the fake-app and prior email phishing campaigns, but those predate the breach by up to three years; only the 2026 physical-mail campaign postdates it, and even that link is speculative rather than confirmed in reporting.
    Proposed correction (not yet applied)
    A January 2024 breach of its third-party support portal exposed contact data for approximately 66,000 users, which has been speculated as a possible contributor to a subsequent phishing campaign delivered via physical mail in 2026; the email phishing and fake-app campaigns that have also targeted Trezor predate this breach.
  2. #4[disputed][awaiting moderator]in section: January 2024 Support Portal Data Breach
    The breach has since been identified as a source of targeting data used in subsequent phishing campaigns including physical mail attacks reported in early 2026.
    reviewerThe January 2024 breach has since been identified as a source of targeting data used in subsequent phishing campaigns including the physical mail attacks reported in early 2026.'Has since been identified as' asserts a confirmed causal link that the cited reporting does not establish; the connection is speculative, not confirmed.
    Proposed correction (not yet applied)
    The breach has been speculated as a possible source of targeting data used in subsequent phishing campaigns including physical mail attacks reported in early 2026.
  3. #11[disputed][awaiting moderator]in the timeline
    2021-04
    reviewerThe fake Trezor app incident dated to April 2021 in the timeline.The timeline date reflects when the incident was reported (April 2021), not when it occurred (January-February 2021), inconsistent with how other timeline entries in this page use occurrence dates rather than report dates.
    Proposed correction (not yet applied)
    2021-01
  4. #13[disputed][awaiting moderator]in section: Physical Mail (Snail Mail) Phishing Campaign — 2026
    Letters sent in Trezor's name claimed recipients must complete a mandatory 'Transaction Check' to avoid losing access to their wallets, with a stated deadline of February 15, 2026.
    reviewerLetters sent in Trezor's name claimed recipients must complete a mandatory 'Transaction Check' to avoid losing access to their wallets, with a stated deadline of February 15, 2026.The page appears to have swapped terminology between the two brand-specific letters described in the source article; the Trezor letter used 'Authentication Check,' not 'Transaction Check.' The deadline date itself (February 15, 2026) is correct for the Trezor letter.
    Proposed correction (not yet applied)
    Letters sent in Trezor's name claimed recipients must complete a mandatory 'Authentication Check' to avoid losing access to their wallets, with a stated deadline of February 15, 2026.
  5. #18[disputed][awaiting moderator]in the timeline
    2025-03-05
    reviewerLedger Donjon's disclosure of the Trezor Safe 3 vulnerability is dated March 5, 2025 in the timeline.March 5 was when Trezor itself disclosed the issue (crediting Ledger's private white-hat report); Ledger Donjon's own public disclosure/write-up was published March 12, 2025. The timeline event text credits the March 5 date to 'Ledger Donjon discloses,' which is imprecise.
    Proposed correction (not yet applied)
    2025-03-12

partially supported

4 claims

The cited evidence supports part of the claim but not all of it.

  1. #7[partially supported][awaiting moderator]in section: Phishing Campaigns Exploiting Trezor's Brand
    A notable abuse vector involved Trezor's own support system: attackers submitted support tickets with phishing messages in the subject line, causing emails appearing to originate from help@trezor.io to be delivered to targeted users.
    reviewerA notable abuse vector involved Trezor's own support system: attackers submitted support tickets with phishing messages in the subject line, causing emails appearing to come from help@trezor.io to be delivered to targeted users.The underlying fact is accurate and correctly cited, but placing it in the same paragraph immediately after the 'February 2023' sentence without a date creates a false impression that it happened around the same time; it is actually a June 2025 incident.
  2. #8[partially supported][awaiting moderator]in section: Phishing Campaigns Exploiting Trezor's Brand
    These emails directed victims to a cloned Trezor Suite application that prompted entry of the recovery phrase, after which funds were immediately transferred.
    reviewerVictims of the support-ticket phishing were directed to a cloned Trezor Suite application that prompted entry of the recovery phrase, after which funds were immediately transferred.The described mechanism is real and documented in independent reporting, but the page attaches it to the support-ticket abuse vector and cites a source that does not contain this detail; the detail actually comes from separate 2023 reporting not listed among this section's sources.
  3. #10[partially supported][awaiting moderator]in section: Fake Trezor Applications (App Store and Google Play)
    A similar counterfeit app subsequently appeared on Google Play.
    reviewerA similar counterfeit app subsequently appeared on Google Play.A Google Play fake-Trezor app is real and documented, but the claimed App Store-then-Google Play sequencing is not clearly supported; available dates suggest the Google Play warning came first or concurrently, not 'subsequently.'
  4. #14[partially supported][awaiting moderator]in section: Physical Mail (Snail Mail) Phishing Campaign — 2026
    The attackers' ability to send physical mail to targeted individuals indicates they possessed customer mailing address data, consistent with the January 2024 support portal breach or with data sourced from previous Ledger breach leaks (which affected hundreds of thousands of users).
    reviewerThe attackers' ability to send physical mail indicates they possessed mailing address data consistent with the January 2024 Trezor breach or data from Ledger's prior breach leaks affecting hundreds of thousands of users.The 'hundreds of thousands' figure for the Ledger breach is accurate, but the specific attribution of this 2026 campaign to either the January 2024 Trezor breach or the Ledger leak is the page's own inference presented with more certainty than the cited source provides.

confirmed

10 claims

The cited evidence supports the claim as written.

  1. #1[confirmed][no action needed]in section: Company Background
    Launched in 2014, Trezor is widely regarded as one of the first commercially available hardware wallets.
    reviewerTrezor is a hardware wallet brand made by SatoshiLabs, headquartered in Prague, Czech Republic, launched in 2014, and is one of the first commercially available hardware wallets, with a product line of Model One, Model T, Safe 3, and Safe 5.Well-established, uncontroversial facts about the company and product line; consistent with independent industry coverage, not just the vendor's own site.
  2. #3[confirmed][no action needed]in section: January 2024 Support Portal Data Breach
    The company secured the breach at 20:20 CET on January 17 and directly notified all potentially affected accounts.
    reviewerTrezor disclosed on January 17, 2024 unauthorized access to its third-party support ticketing portal, secured at 20:20 CET, exposing names/usernames/emails of ~66,000 users who contacted support since December 2021; postal addresses and phone numbers were stored but risk was characterized as low; 41 users were subsequently targeted for seed-phrase phishing; no user funds were directly compromised; the third-party vendor was not publicly named.All discrete sub-facts in this section (date, time, scope, 41 users, no confirmed fund loss, unnamed vendor) match the cited BleepingComputer reporting closely.
  3. #5[confirmed][no action needed]in section: Phishing Campaigns Exploiting Trezor's Brand
    In October 2023, on-chain investigator ZachXBT alerted users via Telegram to a phishing campaign targeting Trezor customers; ZachXBT linked the attack to a possible data breach at Trezor or at Evri, the UK-based delivery company used to ship devices, based on reports from users receiving phishing emails sent only to addresses used to purchase Trezor hardware.
    reviewerIn October 2023, ZachXBT alerted users via Telegram to a phishing campaign targeting Trezor customers and speculated it could stem from a breach at Trezor or at Evri, its UK shipping partner.Confirmed by independent contemporaneous coverage (CryptoRank, Cointelegraph, CryptoNews) of the same October 26, 2023 ZachXBT alert.
  4. #6[confirmed][no action needed]in section: Phishing Campaigns Exploiting Trezor's Brand
    In February 2023, a separate mass phishing campaign sent fraudulent emails and SMS messages directing users to fake Trezor pages.
    reviewerIn February 2023, a separate mass phishing campaign sent fraudulent emails and SMS messages directing Trezor users to fake pages.Independently corroborated timing and mechanism (fake breach notice via SMS/email, February 2023) matches the page's description.
  5. #9[confirmed][no action needed]in section: Fake Trezor Applications (App Store and Google Play)
    One victim, Phillipe Christodoulou, lost 17.1 Bitcoin (valued at approximately $600,000 at the time, exceeding $1 million USD by the time of reporting) after entering his recovery phrase into the fake app.
    reviewerIn early 2021, a fake Trezor app in the Apple App Store was downloaded approximately 1,000 times before removal; Phillipe Christodoulou lost 17.1 BTC worth ~$600,000 at the time (over $1 million by time of reporting); a separate victim lost $14,000 in BTC/ETH.Figures and victim details are accurately reported and match both cited sources.
  6. #12[confirmed][no action needed]in section: Physical Mail (Snail Mail) Phishing Campaign — 2026
    The letters directed recipients to scan a QR code linking to a fraudulent domain (trezor.authentication-check[.]io) that prompted users to enter their 24-word recovery phrase.
    reviewerIn February 2026, BleepingComputer reported a physical mail phishing campaign targeting Trezor and Ledger users, with letters directing victims via QR code to trezor.authentication-check[.]io, requesting recovery phrases, with a stated deadline of February 15, 2026.Domain, deadline, and mechanism are all directly confirmed in the cited BleepingComputer reporting.
  7. #15[confirmed][no action needed]in section: Official X (Twitter) Account Compromise — March 2024
    Approximately $8,100 was stolen from Trezor's associated Zapper account during the incident.
    reviewerOn March 19, 2024, Trezor's official X account was compromised via a phishing attack (initially suspected SIM swap, later confirmed as a Calendly-based phishing campaign that began engaging a Trezor PR employee around February 29, 2024); attackers promoted a fake '$TRZR' Solana token presale; approximately $8,100 was stolen from Trezor's associated Zapper account.All discrete facts (date, SIM-swap-then-phishing narrative, Calendly vector, first-contact date, token name/chain, dollar figure) are corroborated across independent outlets.
  8. #16[confirmed][no action needed]in section: Hardware Device Vulnerabilities
    Unciphered co-founder Eric Michaud stated the exploit could not be patched via firmware and would require a hardware recall.
    reviewerIn May 2023, Unciphered claimed an unpatchable physical extraction vulnerability in the Trezor Model T's STM32 microcontroller via RDP downgrade; co-founder Eric Michaud said it could not be fixed without a hardware recall; Trezor responded that exploitation requires physical theft and sophisticated equipment, and that a strong BIP39 passphrase still protects users.Matches independent reporting closely, including the specific Michaud quote and Trezor's passphrase-mitigation response.
  9. #17[confirmed][no action needed]in section: Hardware Device Vulnerabilities
    In March 2025, Ledger's security research team (Ledger Donjon) disclosed additional vulnerabilities in the Trezor Safe 3 model, identifying that the pre-shared secret linking the Secure Element and the microcontroller (a custom-packaged STM32F429 chip) was stored in flash memory susceptible to voltage glitching attacks.
    reviewerIn March 2025, Ledger Donjon disclosed a voltage-glitching vulnerability in the Trezor Safe 3's STM32F429 microcontroller allowing extraction of a pre-shared secret; the Safe 5's STM32U5 chip was less affected; Trezor patched Safe 3 and Safe 5 firmware.Technical description (chip, attack technique, Safe 5's relative resistance, subsequent patch) is accurate and matches multiple independent reports.
  10. #19[confirmed][no action needed]in section: User Risk Assessment and Safety Guidance
    Use of a strong BIP39 passphrase is recommended by Trezor and independent security researchers as a mitigation against physical extraction attacks.
    reviewerThe primary risk to Trezor users is the ecosystem of impersonation/phishing attacks rather than the hardware itself, and users should treat any request for a 24-word seed, unsolicited support emails, physical letters about mandatory checks, or social media presale/giveaway posts as red flags; a strong BIP39 passphrase mitigates physical extraction risk.This is a reasonable synthesis of risk guidance consistent with vendor advisories and the hardware-vulnerability reporting reviewed elsewhere in this page.
How this fits together. The reviewer reads the published page and its cited sources and records one finding per claim. A human moderator decides whether each proposed correction is applied; those decisions, and the score changes they cause, appear in the audit log. Earlier review runs are not shown here; only the latest reflects the page as it stands.