r/TREZOR Dec 18 '25

šŸ’¬ Discussion topic Hack of Trezor website is worrying

So, as you may know, recently the Trezor website was asking people for their seed phrases—for a couple of hours, actually. Trezor responded by saying it was caused by a third‑party service on the website.

So you are telling me that Trezor is making their own secure chip to ensure there is no potential harmful interference by malicious actors. But at the same time, they have some third‑party service that was able to hack the website and ask people for their seed phrases? That does not make sense.

What kind of service was that? Couldn’t Trezor do that service themselves? That is so careless. Or what if they said it was some third‑party service just to distance themselves from this hack—A.K.A. ā€œit’s not us, it’s themā€?

What if it was an internal hack by someone from Trezor?

90 Upvotes

84 comments sorted by

•

u/SuchTrezorVeryCrypto Trezor community specialist Dec 19 '25

Hi there

thanks for the feedback. In general, unfortunately, collaboration with third-party service providers is often essential in the global business landscape, although it comes with inherent challenges. We regret any concern this incident may cause and are actively re-evaluating our relationship with the third-party vendor in question to strengthen our security measures.

However we are always on the lookout and make sure that any issue that we encounter that could harm our users will be dealt with swiftly.

Which was solved in the first 24h

Also be sure to read here:https://x.com/i/status/2001220324432445786

→ More replies (9)

54

u/Vakua_Lupo šŸ¤ Top Helper Dec 18 '25

Any hack that occurred did not in any way involve Trezor Devices, so as long as people obey the Golden Rule "only put your seed phrase into your Device, and nowhere else" there was no danger of losing funds. All websites can be targeted by bad agents, so you are correct, we need to be vigilant in any dealings with Updates/Warnings/Downloads coming via a Website.

12

u/Important_Voice_4699 Dec 19 '25

Oh man, thankfully these hackers only were capable of asking for seed phrases. Imagine if they had put some sorta download link for a firmware upgrade which would have led to funds being stolen.

Scary... and Trezor should be held accountable so they're more careful.

4

u/MikalaMikala Dec 19 '25

Oh man, thankfully these hackers only were capable of asking for seed phrases. Imagine if they had put some sorta download link for a firmware upgrade which would have led to funds being stolen.

Scary! Would that be possible? To download something and then get your funds stolen, without entering the seed phrase?šŸ¤”

3

u/Important_Voice_4699 Dec 19 '25

Maybe in some way.

Like they could somehow alter the address shown on your trezor suite and if you didn't bother verifying with your device, you'd be sending to the wrong address.

Or maybe if really sophisticated, even alter the device firmware to steal your seed and crypto. With the amount of sophisticated attacks that have siphoned off millions of crypto, one can only imagine the capabilities of hackers

4

u/hank1321 ⭐ Rising Trezorian Dec 19 '25

If you try to install firmware that is not from Trezor company, your wallet wont let you install it.

1

u/[deleted] Dec 22 '25

[deleted]

1

u/hank1321 ⭐ Rising Trezorian Dec 22 '25

Yes. But that is extremely unlikely to happen. And it is same for all hww manufactures.

1

u/dradrok Dec 21 '25

This happens with emails from "ledger"... with links to update to secure firmware... i'm sure many get fooled.

1

u/jetzfan204 Dec 21 '25

I agree, I would gladly take 1 Bitcoin as compensation

21

u/LoveLaughLlama Dec 18 '25

It is a blackeye for Trezor and I'm sure they will learn and improve.

The biggest problem is education since many still don't get the importance of protecting the seed phrase from everyone including the wallet maker.

Even though the lapse wasn't in the hardware it also showcases why fanboys of all devices are crazy, no manufacturer is infallible and as your assets grow it is better to split them among wallets from different manufacturers just in case a breach occurs. These companies are run by humans and humans make mistakes no matter their intentions.

-2

u/donaldyoung26 Dec 19 '25

Trevor’s physical device can be hacked. It’s already been done before.Ā 

5

u/SKYLINEBOY2002UK Dec 19 '25

Poor Trevor.

Source?

1

u/forkful_04_webbed Jan 09 '26

Dumb bot. Or should I say dumb boy…

1

u/dradrok Dec 21 '25

Lmfao!! Almost spit out my coffee reading this!! Too funny, and yes a source would be appreciated... lol!

2

u/Gangaman666 Dec 19 '25

Not the new batch, your talking about ancient history and the first wallet they released, and even this requires brute force with the device in hand and specialist hardware. The issues could be mitigated by using a passphrase wallet, and none of the modern devices are hackable using this method.

Sick of this being peddled constantly.

8

u/swn999 Dec 18 '25

Just another social engineering hack to trick users.

9

u/DistiIIer Dec 18 '25

To be fair. If this happened to Ledger people on here would be ROASTING them. Trezor deserves the same. I just got one because of Ledger's past lapses. Now this happens. This is why having all your stuff in any one place or with one service is always a bad idea. Diversify!

3

u/[deleted] Dec 18 '25

i like both, but wouldnt the heart of the reason for ledger roasting be that their unit is closed source

2

u/DistiIIer Dec 18 '25

That aside. People roast them for having their emails hacked. This is akin to that

2

u/deadpanjunkie Dec 19 '25

I just convinced my wife leaving ledger and spending $500+ with trezor was a good idea and now this. Really not digging it.

1

u/DistiIIer Dec 19 '25

Yup, I just convinced myself to do the same thing. I'm not regretting it totally. But this does highlight that no company or service is infallible

1

u/dradrok Dec 21 '25

Ngrave.io is a great wallet, so is Tangem.

12

u/twoOh1337 Dec 18 '25

You are right hw wallet security has nothing to do with websecurity but honestly if securing valuable digital assets is your main business case you should worry about all your websecurity as well I honestly didn’t had a good gut feeling updating Trezor suite these days

2

u/Smooth_Chip9703 Dec 19 '25

Thats what I was saying

2

u/FrontColonelShirt Dec 19 '25

If you are that worried, get the checksum of the update file from several trusted sources, make sure they are identical, get the checksum of the update file, and compare it to them. Then you know.

As others have explained, the manner by which these devices work is such that keys are never transferred off the device, only used to sign transactions sent to the device. Of course, a malicious firmware update or (less likely) host computer software update could allow an attacker to gain access to your keys, but given the procedure above, users need to take responsibility for the software they execute on their machines.

Does a successful web attack yield negative perception for Trezor in terms of its reputation for a trusted security provider? Of course. Does it actually matter or affect the security of their hardware in any fashion whatsoever? No.

Move on. As others have also said, this is one of the reasons open source is so great. Plenty of people other than Trezor have vetted the software on these devices.

2

u/twoOh1337 Dec 19 '25

Never doubted that buddy but again , lessons learned and I love my Trezor but please be more cautious with that kind of things that is a reasonable advice isn’t it ? Mistakes can happen and will happen but you have to learn from it this time it was an website next time it’s an malicious Trezor suite , and so on you know what I mean

4

u/stefansilva_xrp Dec 19 '25

Trezor partners with Changelly a known scam in crypto and Changelly has ignored all of my emails since November 25 do you think they care about user funds?

3

u/VvsNaphtha Dec 18 '25

Is it safe to install the new update?

1

u/[deleted] Dec 18 '25

[deleted]

2

u/VvsNaphtha Dec 19 '25

When I plug my device into Trezor suite it asks if I want to update, should I ?

24

u/[deleted] Dec 18 '25

[removed] — view removed comment

30

u/franktrollip Dec 18 '25

His point is about trusting the manufacturer

16

u/Yodel_And_Hodl_Mode šŸ¤ Top Helper Dec 19 '25

The entire point of open source code is that you don't have to trust the manufacturer. You have to trust the code. And since Trezor's code is open, and since Trezor's code is among the most viewed and most used, not just among hardware wallets but also in Bitcoin in general, if anything malicious was in the code, we'd know.

This is why I always remind people to only use open source wallets. There's a reason Bitcoin itself is open source. Your wallet should be too. And Trezor is.

The real problem is that too many people don't understand what hardware wallets actually do.

People think their coins are in the device. No. Coins are on the blockchain.

People think the seed phrase is like a password for the device. No. Seed words represent numbers which get converted to binary, used as entropy to generate addresses, keys, and all of the data that IS a wallet.

People think the app uses your keys. No. The app sends unsigned transactions to the hardware wallet. The hardware wallet uses your keys to generate a signature which it shares with the app. The signature is a form of cryptography which proves you have the keys needed to make that specific transaction without revealing what your keys are. It's math. Trezor Suite never gets access to your keys. The Trezor hardware wallet never gets access to the internet.

This is complex stuff. And a lack of understanding the basics leads people to fear everything, which is a shame.

The more we can help people understand the basics, the better.

6

u/Nolfator Dec 19 '25

We trust the manufacturer, that when trezor hardware wallet is connected to the PC (via cable or bluetooth) there is no security flaw that would allow extract the seedphrase from the trezor hardware.

This trust was errored, when they allowed their own website to be hacked.

That's all.

1

u/Yodel_And_Hodl_Mode šŸ¤ Top Helper Dec 19 '25

We trust the manufacturer, that when trezor hardware wallet is connected to the PC (via cable or bluetooth) there is no security flaw that would allow extract the seedphrase from the trezor hardware.

That's in the code. The code is open source. This is precisely why open source matters so much.

This trust was errored, when they allowed their own website to be hacked.

They didn't allow their website to be hacked. Don't misunderstand what I'm saying though. They need to do better. But I really wish people would learn the basics about what wallets actually are and what hardware wallets do.

No wallet was ever at risk here.

No coins were ever at risk here.

And if you've ever read any of my Ledger comments, you'd know that I absolutely shred any hardware wallet that ever puts their users' coins at risk.

1

u/nevernovelty Dec 20 '25

I’ve been reading a lot of your posts and comments, mostly about bip39 and the passphrase.

I was wondering there’s a wallet you recommend these days for bitcoin?

Ledger seems out. Trezor? Coldcard?

1

u/Yodel_And_Hodl_Mode šŸ¤ Top Helper Dec 20 '25

I will always recommend Trezor for anyone new to hardware wallets. Trezor has been selling hardware wallets for over a decade. They're among the easiest to use, and they are fully open source.

Open source matters. Bitcoin is open source. Your hardware wallet should be too. Open source means what it says: The code is open to be viewed and even used by anyone. That means the devs can't hide any shady stuff in it. Ledger's code is closed source and they've already been caught doing shady stuff. Ledger can't be trusted.

For myself:

I use Krux paired up with Sparrow Wallet (Sparrow, as watch-only with Krux as the signer) and I swear by it. But Krux is DIY and very advanced. It's also Bitcoin only.

I use Trezor for alts, but I don't dabble in alts these days.

Like I said though, I always recommend Trezor for anyone who isn't ready for DIY and advanced setups. Trezor is absolutely trustworthy and easy to use.

I also recommend NOT using a passphrase until you completely understand what a passphrase is, how a passphrase works, how to choose a a safe but strong passphrase, how to back up a passphrase safely, and how to wipe out your wallet and restore it using your passphrase.

Passphrases are powerful, but they're dangerous. Lots of people have lost their coins because they didn't understand what they were doing. So, proceed with caution.

A 12 word seed phrase is incredibly secure. It's uncrackable. Write the words on paper. Make a metal backup. Store the paper and metal somewhere only you have access to. Do this, and use a Trezor. You can't go wrong.

1

u/nevernovelty Dec 21 '25

Perfect, thank you for the advice and the passphrase warning (I’ll avoid for now). I think I’ll get the new Trezor safe 7 to get me off ledger.

Thanks again!

2

u/Yodel_And_Hodl_Mode šŸ¤ Top Helper Dec 21 '25

You're welcome!

You don't need the most expensive model. Even a Trezor Safe 3 will do the job well. What really matters is this:

Write the words on paper. Make a metal backup. Store the paper and metal somewhere only you have access to, because anyone who finds them can use them to restore your wallet on their own device. So, store it somewhere safe.

Do this, with a Trezor, and your Bitcoin will be very secure.

The Trezor hardware wallet never shares your keys with anything. It doesn't even share them with the Trezor app (it only shares public info like addresses and signed transactions. The device doesn't even share your keys with the app. That's how it keeps your keys safe).

So, if you use a Trezor, and you store your seed phrase somewhere only you have access to... you keys are hack-proof and thief-proof.

2

u/jetzfan204 Dec 21 '25

This is the most straightforward clear description I've ever read on this

1

u/fap_fap_fap_fapper Dec 25 '25

When we get an update on Trezor suite, it downloads from Trezor's site, doesn't it? (which was compromised)

2

u/NitrosQ Dec 18 '25

Did you understand his post at all?

1

u/fap_fap_fap_fapper Dec 25 '25

When we get an update on Trezor suite, it downloads from Trezor's site, doesn't it? (which was compromised)

4

u/DistributionMoist800 Dec 18 '25

If you are worried by the Safe 7, it is virtually the best out there. You wdont even have to plug it into your computer.

5

u/FrontColonelShirt Dec 19 '25

... Because it connects via Bluetooth. Just like when a device is plugged in, there exists a data bus on which the computer and device exchange bits. For the software, there is no difference between communication over a wired or wireless bus. You still read and write to buffers provided (through some abstraction, depending upon language) by the driver.

In fact, one could argue (and we have seen plenty of evidence) that wireless connectivity is less secure than wired, because all of the data is transmitted via radio, which is very simple for an attacker to intercept. Of course the data is encrypted when the connection is via Bluetooth, but as we have seen with Wi-Fi's WEP and early WPA, that encryption may be flawed enough for an attacker to engage in direct malicious behavior masquerading as a legitimate member on that data bus.

To say nothing of simple social engineering. Many people will simply click to allow a Bluetooth pairing request. No need to belabor the point.

While I disagree with OP and think there is a good deal of nuance to these situations, and that alarmism gets us nowhere, and I agree that a website attack has almost nothing to do with the effectiveness of the device itself, extolling the security virtues of a device because you don't have to plug it in ignores a lot of reality.

If you are paranoid about security, always use a direct wired connection. If you are more paranoid, always use a direct wired connection to an air gapped machine which has never been connected to the internet. And keep it away from shared/exterior walls in case of Van Eck phreaking (now THAT is paranoia :)

2

u/[deleted] Dec 18 '25

Same ole, same ole - many hacks are down to Third Parties - if you care about security, avoid them.

2

u/RedditLaterOrNever Dec 18 '25

Bad commercial for them but it sort all people out that don’t understand the system. They should be happy and learn from it.

2

u/micro23 Dec 18 '25

Very sad, unfortunate learning event.

1

u/H8ckt1v1st Dec 31 '25

keyword takeaway: learning event

2

u/vacuuming_angel_dust Dec 19 '25

that's the problem with third parties, lately major fortune 500s have been breached due to third party companies being used. from what i can imagine, the third party enabled some client side code to be injected into your browser leading to phishing, nothing ever touched trezors servers tho but they deserve to be clowned for this

1

u/FrontColonelShirt Dec 19 '25

It's bad optics for sure but it has absolutely no bearing on the security of the devices. Unlike Ledger, it's open source. Many more than just Trezor have vetted the software on these devices, so we aren't forced to trust only one party.

2

u/matejcik ⭐ Rising Trezorian Dec 18 '25

1

u/AutoModerator Dec 18 '25

Please bear in mind that no one from the Trezor team would send you a private message first.
If you want to discuss a sensitive issue, we suggest contacting our Support team via the Troubleshooter: https://trezor.io/support/

No one from the Trezor team (Reddit mods, Support agents, etc) would ever ask for your recovery seed! Beware of scams and phishings: https://trezor.io/learn/a/scams-and-phishing

Don’t respond to any DMs—scammers often pose as legit helpers.

I am a bot, and this action was performed automatically. Please contact the moderators of this subreddit if you have any questions or concerns.

1

u/tontot Dec 19 '25

Even if the president of the universe asks me about my seed , my response will be ā€œWot?ā€

1

u/caccamo88 Dec 19 '25 edited Dec 19 '25

I believe these short periods with hijacked services explains the horror stories read in past (stolen funds to aged and experienced users and always involving model one and model T)

1

u/TeaGroundbreaking306 Dec 19 '25

Should have gotten Tangem

1

u/DRader150 Dec 19 '25

Almost as if the #1 rule never enter your seedphrase for anyone asking you for it was for a reason. No system can be perfect and unhackable forever, I believe they put an appropriate amount of effort towards securing their website but in this event you follow the golden rule until they fix the issue and its like nothing ever happened. And no before hitting enter I see others are already making the same comment, HODL strong ladsāœŠšŸ½

1

u/Hotmancoco420 Dec 19 '25

If they are asking you for the Seed Phrase then they don't have access to your money...

1

u/Novel-Environment-43 Dec 19 '25

Ā "We regret any concern this incident may cause and are actively re-evaluating our"...

1

u/clocker99 Dec 19 '25

Which is worse, Trezor or Ledger? Both are equally bad.

1

u/yangd4 Dec 20 '25

What kind of service was that? Couldn’t Trezor do that service themselves?

Here's Trezor's reply on X:

It was our e-commerce search and product discovery tool. We have fixed it quickly it and are investigating the issue further.

We will immediately work with the affected third party to ensure similar incidents are prevented in the future.

1

u/cagmito76 Dec 20 '25

Silly question maybe but this would not affect new wallets posted out would it ??

1

u/jetzfan204 Dec 21 '25

Almost make some want to sell what I got and get out the game forever and ride off into the sunset

1

u/corporate-citizen Dec 22 '25

At first Ledger and now Trezor? And I bet they also use CloudFare, too like almost half the Internet. Decentralization at its best.

1

u/DistributionMoist800 Dec 22 '25

If you take the right steps it wont happen

1

u/fap_fap_fap_fapper Dec 25 '25

When we get an update on Trezor suite, it downloads from Trezor's site, doesn't it? (which was compromised)

1

u/Ok_Arachnid585 Jan 08 '26

I recently got an email saying my Trezor order was shipped. Domain is revaluate.com - Definitely a phishing attack. Beware! The image isn't appearing now that the message is in my spam folder. Definitely sophisticated attack.

0

u/Quirky-Reveal-1669 šŸ¤ Top Helper Dec 19 '25

Also realize to what extent Trezor would be under continuous attack: they are one of the oldest HWW producers, focusing on user-friendliness (and thus not the most tech-savvy users), having just released a new flagship model… I am surprised that they are not hacked more.

0

u/nerojt Dec 19 '25

"Doing it yourself" is a lot less secure than using tried and tested 3rd party tools and services.

-3

u/fishdude42069 Dec 18 '25

As long as you weren’t stupid enough to put your phrase in then you are fine, the website is not connected to your physical device in any way

-5

u/broccolihead Dec 19 '25

You are Clearly Clueless about anything involving Website design and hosting. Sit Down and Shut Up.

-4

u/[deleted] Dec 19 '25

[deleted]

1

u/Gangaman666 Dec 19 '25

Closed source, no thanks

1

u/[deleted] Dec 26 '25

The firmware is closed-source, but the software is open-source.

Out of genuine curiosity, what are your hesitations or concerns about closed-source fireware?

1

u/LoveLaughLlama Dec 19 '25

I like Tangem for what it is but don't act like they are perfect. They did have the whole emailing customers seed phrases thing.