ONCHAINSUPPORT

Trezor Phishing After Email Provider Breach: How to Protect Your Wallet

Trezor users face targeted phishing after a third-party email breach. Learn how to verify messages and what to do if a seed phrase was exposed.

Crypto Support Desk
Crypto Support Desk

Crypto Support & Research Desk

Published Sep 20, 2026
Updated Sep 20, 2026
7 min read
Trezor Phishing After Email Provider Breach: How to Protect Your Wallet
Referenced Assets:General Market
Share:

Direct answer: Treat unexpected Trezor security emails, letters, QR codes, and recovery-phrase requests as hostile until independently verified. Trezor confirmed that attackers abused a third-party email provider to send phishing messages to hundreds of thousands of subscribers. Trezor says its wallets and account systems were not breached, but exposed contact information can be reused for highly targeted scams.

What happened?

Trezor disclosed a breach involving email provider Brevo. Reporting says attackers gained access that was incorrectly scoped and used legitimate email infrastructure to send convincing phishing messages. The incident followed an earlier shipping-partner breach that exposed customer contact and delivery information for some hardware-wallet buyers.

Why these phishing messages are dangerous

A message arriving from familiar infrastructure can look more credible than ordinary spam. Attackers may know that the recipient owns a hardware wallet and may know contact or shipping details. That allows them to create personalized warnings about firmware, security vulnerabilities, wallet verification, or account compromise.

How to verify a Trezor security message

Do not use the link in the message

Open a fresh browser window and navigate to Trezor through a bookmark or manually verified official address. Compare any claimed incident with Trezor’s official support and security communications.

Never type a recovery seed into a website

Your recovery phrase controls the wallet. A phishing page that obtains it can recreate the wallet and transfer assets without the hardware device. Trezor support does not need your recovery seed to investigate an email.

Be suspicious of QR codes in physical mail

After prior customer-data exposure, some users reportedly received convincing letters containing QR codes that led to fake wallet pages. A printed letter is not proof that a request is legitimate.

If you already entered your recovery phrase

Assume the seed is compromised. Using a clean device and verified wallet software, create a completely new recovery phrase and move remaining assets to addresses derived from the new seed. Do not reuse the old phrase. If you use passphrases, understand that exposure risk depends on exactly what the attacker obtained, but urgent migration to fresh credentials is the safer incident-response path.

If you only clicked the phishing link

Do not panic, but close the site and assess what information you entered or downloaded. If you entered login credentials, rotate them from a clean device. If you downloaded software, stop using that computer for wallet operations until it has been properly checked. If you only viewed a page and disclosed no secrets, risk may be lower, but remain alert for follow-up attempts.

Scam recovery warning

Victims are often targeted a second time by fake recovery specialists. No legitimate investigator can reverse a blockchain transaction by collecting an upfront crypto fee. Never share a seed phrase, private key, wallet backup, or remote-screen access with someone offering recovery.

Sources

TechCrunch reported the Trezor/Brevo incident and Trezor’s warning that exposed addresses may be targeted again: TechCrunch. Users should independently verify any wallet-security instruction through Trezor’s official website.

FAQ

Were Trezor hardware wallets hacked?

Trezor said its products, wallets, and account system were not compromised in the email-provider incident.

Can Trezor support ask for my recovery phrase?

You should never disclose your recovery phrase to support staff, a website, an email sender, or a caller.

What if I already entered my seed phrase?

Treat it as compromised. Create fresh wallet credentials using verified software on a clean device and move remaining assets.

This article provides general security information and is not investment, legal, tax, or financial advice. For significant losses or suspected device compromise, consider qualified incident-response assistance.

Regulatory & Financial Risk Disclosure

The opinions, research, and analysis expressed in this publication are solely for educational and informational purposes and do not constitute investment, financial, legal, or tax advice. Digital asset markets are speculative and volatile. Past performance does not indicate future results. Always perform independent due diligence.

About the Author

Crypto Support Desk
Crypto Support Desk

Crypto Support & Research Desk

Crypto Support Desk publishes practical, source-led guides to exchange, wallet, network and on-chain service changes. Information is checked against primary or reputable security sources and is not investment advice.

Source-led crypto support research
Trezor Phishing: Protect Your Recovery Phrase | The On-Chain Support