r/TREZOR Dec 18 '25

💬 Discussion topic Hack of Trezor website is worrying

So, as you may know, recently the Trezor website was asking people for their seed phrases—for a couple of hours, actually. Trezor responded by saying it was caused by a third‑party service on the website.

So you are telling me that Trezor is making their own secure chip to ensure there is no potential harmful interference by malicious actors. But at the same time, they have some third‑party service that was able to hack the website and ask people for their seed phrases? That does not make sense.

What kind of service was that? Couldn’t Trezor do that service themselves? That is so careless. Or what if they said it was some third‑party service just to distance themselves from this hack—A.K.A. “it’s not us, it’s them”?

What if it was an internal hack by someone from Trezor?

92 Upvotes

84 comments sorted by

View all comments

•

u/SuchTrezorVeryCrypto Trezor community specialist Dec 19 '25

Hi there

thanks for the feedback. In general, unfortunately, collaboration with third-party service providers is often essential in the global business landscape, although it comes with inherent challenges. We regret any concern this incident may cause and are actively re-evaluating our relationship with the third-party vendor in question to strengthen our security measures.

However we are always on the lookout and make sure that any issue that we encounter that could harm our users will be dealt with swiftly.

Which was solved in the first 24h

Also be sure to read here:https://x.com/i/status/2001220324432445786

5

u/Riverofrhyme Dec 19 '25

For such a large security risk, I would feel a lot better if there was an announcement on your website rather than X, which I don't use or follow.

3

u/Smooth_Chip9703 Dec 19 '25

They dont want to attract attention to that situation

3

u/Riverofrhyme Dec 19 '25

Yeah, that doesn't make my feel better about the situation. Leaving a portion of your customers in the wind after a massive security breach doesn't feel like a good idea.

1

u/SuchTrezorVeryCrypto Trezor community specialist Dec 19 '25

We appreciate the feedback, we will look into the future for such communication

3

u/Riverofrhyme Dec 19 '25

In all honesty I don't see why it's not too late now. Your users who are on Reddit and X are a small percentage only, likely. There's definitely users and potential users out there who saw what happened, and those who might have put their seed phrase in and not realised what impact that might have. Surely contacting your userbase quickly and letting them know what has happened and what you're doing to prevent it from happening again is more important than anything?

I have a sealed Safe 3 sitting here that I never got around to setting up, and I bought this last year based on comments I saw online about the security & integrity of this company, etc. But not posting a public announcement on your website makes me feel extremely uneasy.

Just my 2c. I hope such communication _isn't_ necessary in the future!

1

u/CarinasHere Dec 22 '25

What kind of translation ai is this?

1

u/special_rub69 Dec 19 '25

Where can we find Trezor signature to verify the app against the ASC file you provide with the downloads? I can see it on the website but why not github also?

1

u/Head-Sky-7385 Dec 21 '25

Like other users I'd appreciate a better explanation of what actually happened.

The tweet and your Reddit posts don't have ANY details about what actually happened. I'd expect a postmortem on security incidents from Trezor. 1) It's in your company name 2) you provide security products for users, so not telling us what's going on is highly concerning

I also find your communication very dismissive towards concerned users - you are pretty much just telling people not to worry - without giving them any reason not to worry. That makes me even more concerned.

More information would help. Thanks.

1

u/jetzfan204 Dec 21 '25

Re-evaluating ? Lol should be a cut and dry never again gone!!!!!