Check a Trezor Suite installer with GPG before you run it: the v26.9.2 filenames, the SatoshiLabs key fingerprint, and what a good signature cannot catch.
Yes, if it was strong and never leaked with the seed. The BIP-39 mechanism, which theft scenarios a Trezor passphrase survives, and the ones it does not.
Sender checks failed twice: mailing@trezor.io via Brevo, then help@trezor.io auto-replies. The checks that survive, in one table, plus Trezor's own rules.
The STM32 entropy alert is phishing sent through Trezor's breached Brevo account on 9 September. What BitBox and CoinTracking received, and what to do.
Trezor aimed to have its Anonymous Delivery option live in the EU by September 2026. The company's own incident page still lists it as coming soon — and here is the narrow threat it would actually defend against.
One device answers the trust question with auditable silicon and a colour touchscreen; the other signs Bitcoin only, behind an air gap, after a summer that broke its own seed generator. What each defends, and against whom.