To verify a Trezor Suite download is genuine, save the installer, its matching .asc signature and the SatoshiLabs 2021 signing key from Trezor’s download page, import the key into GPG and run gpg —verify on the .asc file. Trezor’s guide says a genuine file returns Good signature from “SatoshiLabs 2021 Signing Key”.

The rest is the threat verification answers, the current filenames, and what a signature cannot prove. This desk read Trezor’s Download and verify guide and the v26.9.2 release on GitHub on 23 September 2026. We ran no gpg command: the expected outputs below are what Trezor’s guide says you should see.

Why verify a Trezor Suite download at all?

Because the fake installer is a working attack. In the Brevo newsletter phishing of 9 September 2026, Trezor’s statement, as reported by BleepingComputer, says the emails linked to a download of an app that asked for the wallet backup, and about 2,500 people clicked before the domain came down within 20 minutes. The guide states the defence plainly: if the installer were a fake, signature verification would fail and warn you that the fingerprints do not match. Checking the sender is covered in how to tell if a Trezor email is real.

Which files do you need for Trezor Suite v26.9.2?

As of 23 September 2026, GitHub marks v26.9.2 as the latest release, with its assets uploaded on 15 September. Trezor’s guide still demonstrates 22.4.3 filenames and says to replace the version with the latest release. For v26.9.2 that means:

PlatformInstallerSignature file
WindowsTrezor-Suite-26.9.2-win-x64.exeTrezor-Suite-26.9.2-win-x64.exe.asc
macOS, arm64Trezor-Suite-26.9.2-mac-arm64.dmgTrezor-Suite-26.9.2-mac-arm64.dmg.asc
macOS, x64Trezor-Suite-26.9.2-mac-x64.dmgTrezor-Suite-26.9.2-mac-x64.dmg.asc
Linux, x86_64Trezor-Suite-26.9.2-linux-x86_64.AppImageTrezor-Suite-26.9.2-linux-x86_64.AppImage.asc
Linux, arm64Trezor-Suite-26.9.2-linux-arm64.AppImageTrezor-Suite-26.9.2-linux-arm64.AppImage.asc

The Mac builds also ship as .zip files, each with its own .asc. The guide says to fetch the key file, satoshilabs-2021-signing-key.asc, and the signature by clicking More on the Trezor Suite download page, and to keep all three files in one folder. This desk could not read which version trezor.io serves, because its download list renders by script; match your filenames to what it offers. GitHub’s sha256 digest beside each asset is computed by GitHub, not published by Trezor; GPG is the method Trezor documents.

How to verify the Trezor Suite signature on Linux and macOS

gpg --import satoshilabs-2021-signing-key.asc
gpg --verify Trezor-Suite-26.9.2-linux-x86_64.AppImage.asc

On macOS the guide uses a GPG utility such as GPG Suite and the same two commands against the .dmg.asc file. On Linux it then marks the AppImage executable with chmod u+x, and notes that Debian, CentOS and similar distributions may need a —no-sandbox flag.

How to verify Trezor Suite with Kleopatra on Windows

Install Gpg4win, which includes Kleopatra. Import the key through File > Import, then choose File > Decrypt / Verify and select Trezor-Suite-26.9.2-win-x64.exe. The guide says a “data could not be verified” message can be ignored if you did not mark the certificate as valid. Before closing, click Show Audit Log and look for the Good signature line.

What does a good signature not protect against?

ThreatDoes a good signature catch it?
Fake installer from a phishing linkYes: verification fails, per Trezor’s guide
Fake key served beside a fake fileOnly if you compare the fingerprint to Trezor’s
Malware already on the PC, inside the real appNo
Anyone asking for your recovery phraseNo: that is a rule, not a file check

Kaspersky’s GReAT research, as reported by The Hacker News on 15 July 2026, describes an OkoBot module, SeedHunter, that injects into an installed Trezor Suite, Ledger Wallet or Ledger Live on infected Windows machines and draws a fake recovery page inside the genuine app. Our reading, not Kaspersky’s: a signature checks the file you install, and cannot see malware that arrives by another route. Trezor’s scams page covers the fourth row, saying any request for your wallet backup, PIN, passwords or codes is always a scam. If you have already typed the words in, start with what to do after entering your seed on a phishing site.

Trezor Suite verification: questions readers ask

Is it necessary to verify Trezor Suite before installing?

It is optional, and it is a check that catches a fake installer. Your keys stay on the device, but a counterfeit app can still ask you for the words that rebuild them, which is what the September 2026 phishing download did. Trezor’s guide says a fake file would fail verification. A GPG check is cheap insurance against the attack that is actually happening.

What does ‘This key is not certified with a trusted signature’ mean?

Trezor’s guide says the warning appears unless you tell GPG to trust the key, and it just means no third-party authority has certified that key. It does not mean the file is bad. What matters is the line above it, Good signature from SatoshiLabs 2021 Signing Key, and a primary key fingerprint that matches EB48 3B26 B078 A4AA 1B6F 425E E21B 6950 A2EC B65C.

What should Good signature from SatoshiLabs 2021 Signing Key look like?

GPG prints the words Good signature from “SatoshiLabs 2021 Signing Key” and, per Trezor’s guide, a primary key fingerprint of EB48 3B26 B078 A4AA 1B6F 425E E21B 6950 A2EC B65C. In Kleopatra the same line appears under Show Audit Log. BAD signature, a different key name or a different fingerprint means you delete the file and download it again from Trezor.

The briefing, once more: a seed is never typed into a keyboard, never photographed, never stored in a cloud, never given to support. This is Trezor’s published procedure as read on 23 September 2026, not a test of it. Crypto assets are high risk, nothing here is financial advice, and self-custody means self-responsibility: read the guide yourself before you install.