Don't Take the Bait
If you own a crypto wallet like Trezor, your inbox might one day get a message that looks official but is actually a cleverly disguised trap. That’s exactly what happened with this recent phishing attempt making the rounds.
Here’s one of the emails we received:
On the surface, it looks polished – a logo, convincing jargon, even an address in Prague. But beneath the surface, it’s a classic phishing scam designed to get you to click a malicious link and hand over your recovery seed.
Red Flags in This Email
- Suspicious Sender Address
- Trezor’s official emails come from domains like @trezor.io – not @runloyal.com.
Scammers often use random domains that have nothing to do with the brand. - Urgency + Threat of Limited Access
- The email says you must act now, or your account will be limited. Urgency is a common scam tactic to bypass your normal caution.
- Mandatory "Security Update"
- Hardware wallets never require urgent updates via email. Real updates are announced on the official Trezor website and performed through the official Trezor Suite software, not by clicking an email link.
- Unverified Organisation Name
- “International Digital Asset Consortium (IDAC)” sounds official… but it doesn’t exist. Scammers love creating fake authorities to make their story sound credible.
- Clickbait Call-to-Action
- The “Navigate To Suite” button is the bait. One click could lead to a fake site that steals your recovery phrase.
What To Do If You Receive an Email Like This
- Stop and inspect. Before clicking anything, check the sender’s address, hover over links to see where they lead, and look for inconsistencies.
- Verify with the source. Visit Trezor’s official website directly – not through the email – or check their verified social media accounts for announcements.
- Report it. Forward phishing emails to Trezor’s security team at security@trezor.io and to your email provider’s abuse department.
- Delete it. Once reported, remove it from your inbox so you don’t accidentally click it later.
What Not To Do
- Don’t click the link. Even if you’re curious, visiting the fake site can expose you to malware or keyloggers.
- Don’t enter your recovery seed. Trezor, Ledger, and all legitimate wallet providers will never ask for it via email, pop-up, or phone call.
- Don’t reply to the sender. It confirms your email is active, making you a target for more scams.
Here’s the Advice Directly from Trezor |
---|
Trezor recently issued a warning about the sharp rise in phishing scams targeting hardware wallet owners. These scams don’t just impersonate Trezor – they also pose as exchanges, other wallet brands, and even fake “Trezor Support” phone calls. Common scam tactics Trezor has seen:
Trezor’s golden rule:The only time you’ll enter your wallet backup (recovery seed) is directly on your Trezor device when restoring a wallet. This means:
Trezor also stresses:
Official contact points:Trezor’s authentic site and downloads: trezor.io Official email sender: noreply@trezor.io They will never ask for your recovery seed over email, phone, DM, or on any website. How Trezor is fighting scams:
|
The Final Buzz
Crypto phishing emails are getting more sophisticated, but the scammer’s goal hasn’t changed – trick you into giving away the keys to your digital vault.
Remember:
If someone asks for your recovery phrase, it’s a scam. Every. Single. Time.
Keep your wallet secure by staying skeptical, verifying every message, and never letting urgency override caution.
Stay safe. Stay smart. Be Crypto Safe.
Education is your best defence. Unlock member-only guides, checklists, and tools designed to protect your crypto, stay safe and be compliant.