‘Your Wallet Doesn’t Decide When You Need Your Backup’: Trezor Analyst on the Fake App Problem
A fake wallet can reach users through a search ad, an app-store listing or a letter with a QR code. Lucien Bourdon, a Bitcoin Analyst at Trezor, says these scams often end with the same demand: enter the words that can restore your wallet.
- Scammers use urgency and familiar wallet brands to win trust.
- A recovery phrase restores a wallet. It is not for installing an update.
- Recovery procedures vary by wallet and device. Follow the maker’s instructions.
- A screen that looks genuine does not make a request for your phrase safe.
Different disguises, same request
Scammers may pose as wallet support, warn of a security vulnerability, set a fake authentication deadline or promise an airdrop. The pitch changes, but Bourdon says the goal is often to get users to enter their seed phrase.
“The method changes each time, but the last step is always a screen asking for the seed phrase.”
A seed phrase, also called a wallet backup, is a sequence of words used to restore a wallet. Anyone who gets it may be able to take control of the wallet and its funds. A fake recovery screen is more than an annoying imitation. It can be the final step in a theft.
In an interview with U.Today, Bourdon described three reported campaigns. He said that in August, people searching Google for “Trezor wallet” clicked a sponsored result that led to a fake Trezor Suite page built on Google Sites. According to the account, one address received about 24 BTC across roughly 80 deposits.
Bourdon also described a fake Ledger Live app that appeared on Apple’s Mac App Store in April. The interview said about 50 people downloaded it and entered their seed phrases. Around $9.5 million was lost before Apple removed the listing.
In February, people reportedly received printed letters branded as hardware-wallet companies. The letters warned of a fake authentication deadline and included QR codes leading to copied recovery screens that requested 12, 20 or 24 words. The interview did not identify the companies or explain which backup format the 20-word request referred to. It should not be taken as a standard phrase length.
The interview does not provide a publication date, so the calendar years for these incidents cannot be established from the account. It also does not cite supporting records or explain how the reported totals and victim counts were calculated. Treat those figures as claims from the interview, not independently verified measurements. Bourdon said there was no indication that the three campaigns were connected.
When should you enter a wallet backup?
A seed phrase is used to restore a wallet when you choose to do so, for example, after losing access to a device or moving to a new one. You should not need it for a routine update.
“No update ever needs it, including security patches, whether you use a hardware wallet or a software one.”
For hardware wallets, Bourdon advises entering the backup on the device itself, rather than typing it into a computer or phone. Recovery methods vary by model, so follow the manufacturer’s instructions for your device. If a website or computer application asks you to type a hardware-wallet backup using a keyboard, stop and check the instructions through the manufacturer’s official channels.
Software wallets, such as MetaMask and Trust Wallet, run on computers or phones. Their documented recovery processes may involve entering a seed phrase on that device. That does not mean an unexpected prompt is safe. Start from the wallet maker’s official website or a verified app-store listing, not a link in a message, and follow the wallet’s published recovery steps.
Bourdon also warns that malware can display a fake page within a genuine app. The interview does not explain how those deceptive screens are presented, but the point is clear: a familiar logo or polished design cannot prove that a prompt is genuine.
“So how an app looks on your computer or phone tells you nothing about whether it's genuine.”
Urgency is part of the attack
A warning about a vulnerability, a deadline to “authenticate” a wallet or a limited-time airdrop can pressure people to act before they verify the request. Pause before following any instruction to restore a wallet, especially if you did not start the recovery yourself.
Bourdon says Trezor may send legitimate order updates or security notices, but it does not ask users for seed phrases or other private information. He says Trezor support does not contact users first. If you receive an unexpected message, even if you have contacted support before, verify it independently. Do not use the message’s links or phone numbers. Go to trezor.io directly and use the contact options there.
Questions to ask before entering a seed phrase
-
Does a legitimate wallet update need my seed phrase?
No. Bourdon says updates, including security patches, do not require it. A request for your phrase to install an update is a serious warning sign.
-
Can a software wallet ask for my seed phrase?
It may be part of a recovery you deliberately started. Use the wallet maker’s official site or a verified app-store listing, and follow its documented recovery steps.
-
Where should I enter a hardware-wallet backup?
Bourdon advises entering it on the hardware device, not typing it into a computer or phone. Recovery methods vary, so check the manufacturer’s instructions for your specific model.
-
What should I do with a suspicious Trezor message?
Avoid its links and phone numbers. Visit trezor.io directly and verify the message through Trezor’s official support channels.
Your backup is for a recovery you choose to begin, not a deadline someone else imposes. For another example of hardware-wallet security questions, see the Trezor Safe 7 secure element flaw reported in lab testing.