Worked example · 2025-20
Trezor-impersonating physical-mail seed-phrase phishing campaign — 2025–2026
Summary
Beginning in 2025, cryptocurrency users — particularly Trezor hardware-wallet owners whose physical addresses appear in breach compilations — received physical letters purporting to be from Trezor's security team. The letters used Trezor's logo, product imagery, and security-branded language to instruct recipients to visit a typosquat domain and enter their BIP39 seed phrase under the pretext of a "critical security update" or "firmware vulnerability remediation."
The campaign's key operational characteristics: (1) the typosquat domains were registered shortly before letter distribution, with near-miss Levenshtein distances to trezor.io; (2) the domains served a Trezor-branded web UI that guided victims through entering their 12/24-word seed phrase; (3) the physical letters included a QR code linking directly to the typosquat domain — exploiting the QR-code trust heuristic common in hardware-wallet setup flows.
Trezor published a security advisory confirming that the campaign was not a legitimate communication and reiterating that Trezor never asks for seed phrases via any channel. The campaign remained active through early 2026 at v0.1 cutoff.
Public references
- Trezor security advisories: physical-mail phishing campaign warning (2025).
- Kaspersky Threat Intelligence: physical-mail phishing campaign tracking (2025-2026).
- Domain registration data for typosquat domains targeting
trezor.io(Certificate Transparency logs).