Worried your Trezor wallet has been hacked? Take a breath. In the overwhelming majority of “my Trezor got hacked” cases we see, the device itself was never touched. The crypto is still on the blockchain, and the loss, if there even is one, came from a scam or a lost credential, not from someone remotely breaking into the device.
The phrase people type in a panic, “Trezor wallet hacked,” almost always traces back to a scam or a lost credential, not a broken device. That said, we won’t sugar-coat it. The honest question “can a Trezor be hacked?” has a nuanced answer, and pretending otherwise would do you no favours. In this guide we’ll separate myth from fact: whether a Trezor wallet can be hacked, the real, documented Trezor hacks that exist, what actually puts your crypto at risk, and what to do if you think you’ve been compromised.
Can a Trezor Wallet Be Hacked? The Honest Answer
Here’s the short version. No one has ever remotely hacked a Trezor over the internet to drain funds. Your private keys are generated and stored on the device and never leave it, so there’s no online “door” for an attacker to walk through from afar.
But “can a Trezor be hacked” is not the same question as “can a Trezor be hacked remotely.” With the physical device in hand, specialist equipment, and time, security researchers have extracted seeds from older Trezor models in a lab. That’s a very different threat from a hacker on the other side of the world, and understanding the difference is the whole point of this article.
So the accurate answer is: a Trezor is extremely secure against remote attacks, vulnerable to sophisticated physical attacks on older models if someone steals the device, and, like every wallet, only as safe as the human using it. Let’s look at the actual cases.
Has Trezor Ever Been Hacked? The Documented Cases
Yes, Trezor has been “hacked” in a laboratory sense, twice in well-known cases. Both required the physical device, and both are defeated by a passphrase. Neither was a remote attack.
The Kraken Security Labs voltage-glitch attack (2020)
In 2020, Kraken Security Labs demonstrated that a Trezor One or Trezor Model T could be opened up and, using a technique called voltage glitching, have its read protection downgraded so the encrypted seed could be dumped from the chip. They reported it took roughly 15 minutes of physical access. After extracting the encrypted data, a short PIN could then be brute-forced.
Two things matter here. First, the attack could not be done remotely: it needed the device in hand and hardware tampering. Second, Kraken’s own recommended fix was to enable a BIP39 passphrase, because the passphrase is never stored on the device and this attack cannot recover it. The weakness came from the general-purpose chip used, not from Trezor’s software.
The Unciphered physical hack (2023)
In 2023, the security firm Unciphered showed, in a video using a device supplied by CoinDesk, that they could extract the seed and PIN from a Trezor Model T they physically possessed. They used an unpatchable vulnerability in the STM32 chip, the same class of “RDP downgrade” weakness that had been flagged years earlier.
Again, the same caveats apply. It only works with the device in the attacker’s physical possession, it can’t be patched on units already shipped because the flaw is in the chip itself, and Trezor noted that a strong passphrase renders the attack useless.
What these Trezor hacks do and don’t mean
Put plainly: if you own an older Trezor, keep it in your possession, and use a passphrase, these headline “Trezor hacked” stories are not a realistic threat to you. They describe expert teams with lab equipment and stolen hardware, not someone hacking your wallet while it sits in your drawer. And Trezor’s newer Safe family (Safe 3, Safe 5, and Safe 7) added a dedicated EAL6+ secure element specifically to resist this type of physical attack.
The Real Way People Lose Crypto: Phishing and Scams
Here’s the uncomfortable truth. Almost every real-world loss involving a Trezor comes not from a cracked device, but from a person being tricked into giving away their seed phrase or approving a malicious transaction. The attackers don’t beat the hardware. They beat the human.
These campaigns often abuse Trezor’s brand and channels to look legitimate. In 2022, attackers used customer email addresses stolen from a third-party newsletter provider to send convincing fake Trezor emails. In 2025, criminals abused Trezor’s public support contact form so that automated replies came from the genuine help@trezor.io address, lending their phishing messages an air of authenticity. In both cases, Trezor’s own systems and the devices were not breached, and no seed was extracted through Trezor. The goal was simply to lure users to a fake site that asked them to type in their recovery seed.
That last point is the golden rule. No legitimate service, Trezor included, will ever ask you to enter your seed phrase on a website. If a page or email asks for it, it’s a scam, full stop.
How Trezor Actually Protects Your Crypto
It helps to know what stands between an attacker and your funds, because these layers are exactly why remote hacking isn’t realistic.
Your PIN locks the physical device and can’t be brute-forced, thanks to a randomized keypad and an exponentially growing delay that ends in a wipe. If you ever forget your Trezor PIN, you restore from your seed rather than “cracking” anything. Your passphrase, often called the 25th word, creates a hidden wallet that isn’t stored on the device at all, which is precisely why it defeats the physical attacks above. If you’ve lost your Trezor passphrase, that hidden wallet is the one holding your funds. On newer Safe models, an EAL6+ secure element adds hardware-level resistance to physical tampering, and Shamir Backup lets you split your seed into multiple shares so a single stolen copy isn’t enough.
Signs Your Trezor or Wallet May Be Compromised
Most “I’ve been hacked” scares turn out to be something harmless, like an empty hidden wallet or a derivation-path mismatch. Still, treat these as genuine red flags: transactions you did not authorise leaving your accounts, a passphrase or PIN that suddenly stops working when it always worked before, an email or site that asked you to enter your seed and you did, or a device that arrived with a pre-filled seed card or “activation” instructions (a classic supply-chain scam, since a real Trezor always generates your seed during your own setup).
If you only see an empty balance but never shared your seed, don’t panic. It’s far more likely a missing passphrase or a wrong account type than a hack. Our guide on a lost or invalid Trezor seed phrase covers those cases.
What to Do If You Think Your Trezor Was Hacked
Act calmly and in order.
- If you still control a secure device and your seed, move your funds first. Set up a brand-new wallet on a device you trust, ideally with a fresh seed and a passphrase, and transfer everything to it immediately. Our Trezor wallet recovery guide walks through the restore process.
- Never enter your seed on any website, even one that looks like Trezor. Use only the device and official Trezor Suite.
- Stop interacting with the suspicious email, site, or “support agent.” Do not pay anyone promising to reverse a transaction.
- If your problem is lost access rather than theft (a forgotten PIN, a misplaced passphrase, or a damaged seed card), that is recoverable, and it’s exactly what we help with.
One honest limitation you deserve to hear up front: if a thief has already moved your coins to their own address on the blockchain, that transaction is irreversible. No service, ours included, can claw back funds that have already left your wallet. Anyone who guarantees they can is running a scam. What a legitimate recovery service can do is help you regain access to a wallet that is still yours.
How Crypto Recovers Can Help
If you’ve lost access to your own Trezor, a forgotten PIN, a lost or partial seed, or a forgotten passphrase, that’s our specialty. We start with a free, honest assessment of your chances, work on a success basis, and never ask for your seed phrase upfront. We’ll also tell you plainly when a case isn’t recoverable rather than take you on a false hope.
If you’re worried about a possible compromise and want a clear-headed second opinion before you act, get in touch or start with our Trezor recovery service.
Trezor Hacked FAQ
Can a Trezor be hacked remotely?
No. There is no documented case of a Trezor being hacked remotely to steal funds. Your private keys never leave the device, so there is no online path for a remote attacker. Remote losses come from phishing, not from breaking the device.
Has Trezor ever been hacked?
In a lab sense, yes. Kraken Security Labs (2020) and Unciphered (2023) both extracted seeds from Trezor devices they physically possessed, using a chip-level vulnerability on older models. Both attacks require the physical device and are defeated by a passphrase.
Can Trezor be hacked if someone steals the device?
On older models, a highly skilled attacker with lab equipment could potentially extract the seed, which is why a passphrase matters so much: it isn’t stored on the device and blocks those attacks. Newer Trezor Safe models add a secure element that resists physical extraction.
Is a Trezor still safe to use?
Yes, for the vast majority of people a Trezor is very safe. The practical risk isn’t the hardware, it’s phishing. Use a passphrase, keep the device in your possession, and never enter your seed on any website.
Can a hacked Trezor’s stolen crypto be recovered?
If the coins have already been moved on-chain by the attacker, no. Blockchain transactions are irreversible. Recovery services can only help you regain access to a wallet that is still yours, such as after a forgotten PIN or passphrase.











