If you entered your Trezor seed phrase on a phishing site, treat the wallet as stolen. Move every coin to a wallet built on a new backup first, wipe the Trezor and set it up with a fresh, date-marked backup second, and report the message to Trezor third. Do not wipe before you move.

That is the whole of what to do if you entered your Trezor seed phrase on a phishing site; the rest is the order of operations behind it, from Trezor’s own guides, which this desk read on 19 September 2026. It is live because of the Brevo newsletter incident: on 17 September Trezor updated its incident post with Brevo’s confirmed figure of 347,149 exported contacts and a warning of more targeted phishing. The first wave’s link, per Trezor, led to a download asking for the wallet backup, and about 2,500 people clicked before the domain came down within 20 minutes.

What to do if you entered your Trezor seed phrase on a phishing site

Trezor’s guide on moving crypto to a new backup says: if you suspect your backup has been compromised, assume it has and move your funds immediately; doing the steps promptly and in sequence minimises the window in which funds can be drained.

  1. Move the funds to a wallet whose backup the attacker has never seen. The routes are below.
  2. Wipe the Trezor and set it up again. Create a new backup and, in the guide’s words, mark it as your new backup, for example with the date of creation.
  3. Bring the funds home to addresses generated in Trezor Suite and confirmed on the device screen.
  4. Report it through Chatbot Hal, per Trezor’s scams page.

Never type the old seed anywhere to “check” it, and never wipe before the funds have left: the wipe destroys nothing the attacker holds.

What did you type in, and what can the attacker now do?

None of the pages this desk read, Trezor’s blog and Learn pages and the readable part of the top-ranked vendor post, separates these cases.

What you enteredWhat the attacker can now doThe fix
Seed words onlyRegenerate your standard wallet on any device and empty itMove funds to a new backup now, then wipe
Seed plus passphraseThe above, plus that hidden wallet, since Trezor says one needs both backup and exact passphraseEmpty the hidden wallet too, then wipe
Seed, passphrase never typedStandard wallet only; each passphrase makes a different walletMove the standard wallet; the hidden one still needs a new backup
PIN onlyNothing without the physical device, which the PIN, per Trezor, stops them unlockingChange the PIN; protect your home address
Email address onlySend better-aimed lures; that is what the Brevo export exposedExpect follow-ups; nothing on-chain is at risk

On the PIN row: Trezor’s Learn page on security threats says the Safe 7 resets and erases after 10 wrong attempts, the Safe 5 and Safe 3 after 16, and the Model T and Model One have no hardware-enforced limit. A leaked PIN is a courier-and-burglar problem, not an internet one, and August’s courier data breaches are why the address matters.

How do you move funds when you only own one Trezor?

Trezor’s move-to-a-new-backup guide gives three routes.

A second Trezor. Initialise the spare, date-mark its backup, verify it with the check-backup process, generate addresses, send from the compromised wallet.

A hot wallet as a bridge. Under time pressure, send to a compatible software wallet, wipe the Trezor, set it up with a new backup, bring the coins back. The guide says this exposes your coins to a potentially dangerous environment and should only be done in emergencies.

One device, cold storage only. The guide calls this relatively complicated: confirm the old backup is valid before starting and do not destroy it until the process is complete.

Should I reset my Trezor after a phishing attempt?

If you only clicked, no. Trezor’s incident post says that if you have not entered your wallet backup anywhere other than on your Trezor during recovery, your assets remain secure. That is a statement about this campaign, whose link led to an app asking for the backup; a page that installs malware is a different threat model. If you entered the backup, yes, but as step two, after the funds have moved. Sender checks are in our piece on telling a real Trezor email from a fake one.

Questions readers ask

What happens if someone has your Trezor seed phrase?

They have the wallet. Trezor’s Learn page says that if they get your wallet backup they can move your funds, and every transaction is final and irreversible by design. The PIN does not help, because the attacker does not need your device. Only a hidden wallet whose passphrase was never typed in stays out of reach.

Does Trezor ever ask for your recovery seed?

No. Trezor’s scams page says any request for your wallet backup, PIN, passwords or codes is always a scam, and that it will never contact you about your wallet backup or ask you to perform actions with your wallet. The only legitimate actions it lists are updating device firmware and Trezor Suite through the desktop app.

Can Trezor deactivate my device?

No. The company states on its scams page that it cannot and will not deactivate your device and has no physical ability to affect it in any way. Any message saying your Trezor will be disabled unless you act is, by its own page, a scam built to create panic.

How do I report a phishing email to Trezor?

Through Chatbot Hal on Trezor’s support pages. Its Learn page says to type the words I want to report phishing to Hal and follow the instructions, so the company can warn others. Do it after your funds have moved, not before.

The briefing, once more: a seed is never typed into a keyboard, never photographed, never stored in a cloud, never given to support. This is Trezor’s published procedure as read on 19 September 2026, not a test of it. Crypto assets are high risk, nothing here is financial advice, and self-custody means self-responsibility: read the guide yourself before you move a coin.