How to tell if a Trezor email is real, even from @trezor.io
Sender checks failed twice: mailing@trezor.io via Brevo, then help@trezor.io auto-replies. The checks that survive, in one table, plus Trezor's own rules.
To tell if a Trezor email is real, judge what it asks, not who sent it. Any message asking for your wallet backup, PIN, passwords or codes is a scam, whatever the sender shows, per Trezor’s guidance; the only legitimate actions are firmware and Trezor Suite updates. Confirm on the device, and contact Trezor through a channel you open yourself.
Why checking the sender is not enough for a Trezor email
Trezor’s scams-and-phishing page on trezor.io/learn tells readers to watch for lookalike addresses, giving @trezorr.io as the example of a misspelt @trezor.io.
On 9 September 2026 it was not. Trezor’s statement, dated 10 September, says Brevo, the third-party platform it uses for newsletter campaigns, suffered an incident affecting 120 Brevo accounts, and an unauthorised actor used Brevo’s system to send email from customer accounts including Trezor’s. The lure, subject line Critical Security Alert: STM32 Entropy Vulnerability, linked to an app download that asked for the wallet backup. Per The Register, people who shared copies said the messages appeared to come from mailing@trezor.io, and because the legitimate provider was compromised the messages could pass authentication checks. We covered that message as news; this is the procedure it left behind.
It was not the first genuine sender. In 2025, per BleepingComputer, Trezor’s support site let anyone open a ticket with any subject line and auto-replied from the legitimate help@trezor.io address, so attackers wrote the pitch into the ticket title.
Which checks survive a compromised sender?
This desk read Trezor’s Brevo statement, its scams-and-phishing page, The Register’s report and BleepingComputer’s report on 14 September 2026 and set each recommended check against the two incidents.
How to tell if a Trezor email is real: the procedure
- Read the ask. If the email wants your wallet backup, PIN, passphrase, any code, an app download to verify or secure your seed, or any action with your wallet, it is phishing. Trezor’s page says every message urging you to verify your backup can be assumed to be a phishing attempt.
- Read the urgency. A deadline, a threatened suspension or a critical vulnerability with a link is the shape of both real incidents, and Trezor’s page lists it as a red flag.
- Do not use the link, even if the domain looks right. Open Trezor Suite or type trezor.io yourself. Trezor’s warning about this incident went into Suite without the email, per its statement.
- Only now check the sender. A lookalike such as @trezorr.io is a certain fail. A genuine @trezor.io is not a pass, for the reasons in the table.
- Confirm on the device. Firmware and Suite updates, the only actions Trezor says you will ever need, are confirmed on the Trezor’s own screen. Our Safe 7 review covers what that screen does and does not protect.
How often has a real Trezor address carried phishing?
The 347,000 addresses are the lasting part: Trezor says they might be used for other phishing attacks in the future, and that, as of its statement, the Brevo account is suspended and email sending disabled. Add the courier list from the ShipMonk breach and the next message may be better than the last.
What email address does Trezor use?
Two, in the sources this desk read: mailing@trezor.io, reported by The Register as the apparent sender of the September 2026 newsletter phishing, and help@trezor.io, whose automated support replies were abused in 2025, per BleepingComputer. We found no published list of Trezor sending addresses in the pages we read, so the address is a clue, never proof.
Will Trezor ever ask for my recovery seed?
No. Trezor’s scams-and-phishing page states that any request for your wallet backup, PIN, passwords or codes is always a scam, that Trezor will never contact you about your wallet backup, and that the only legitimate actions are firmware and Trezor Suite updates through the desktop app. Its 10 September 2026 statement repeats the promise.
How do I report a phishing email to Trezor?
Trezor’s scams-and-phishing page tells anyone phoned by someone claiming to be Trezor to hang up and open a ticket through its Chatbot Hal, tells anyone else approached to use official Trezor channels, and carries a section headed How to report Phishing Scams. Open that channel yourself, from an address you typed, never from a link in the message, then delete the email, as Trezor’s Brevo statement advises.
The briefing does not change with the sender. The recovery phrase belongs on paper or metal, offline: never typed into a keyboard, never photographed, never stored in a cloud, never given to support, and never entered into anything an email sent you, however genuine the address. Crypto assets carry high risk, none of this is financial advice, and self-custody puts the inbox on your side of the desk, so read Trezor’s own guidance yourself.