Creators of the first-ever hardware wallet (2014). Securing crypto for 2M+ users worldwide. 100% open source. Take control. Tweets are not intended for the UK.

Pinned Tweet
Stay alert for scams ⚠️ Please remember: • Trezor will never call, email, or send you letters asking for your wallet backup, aka recovery seed (12, 20, or 24 words) • Never share your wallet backup with anyone • Only enter your wallet backup directly on your Trezor device during recovery • Trezor support will never ask for your wallet backup • Never follow wallet-migration instructions from unsolicited emails, messages, or phone calls There are websites impersonating Trezor, including fake sites appearing in sponsored search results. These sites can look extremely convincing. Entering your wallet backup on one of them could result in your funds being stolen. Don't assume a sponsored search result is legitimate. Always verify that you're using the official Trezor website: trezor.io
71
38
391
57,243
A wrap on “The Coldcard aftermath” panel at @btchelevent. Trezor CEO @matej_zak joined the main stage to discuss what the hack exposed about supply chains, firmware, and open source, and the lessons for users and manufacturers.
4
2
15
2,198
Meet us at @btchelevent in Helsinki 🇫🇮
2
4
44
7,236
Trezor retweeted
300,000+ ETH now staked with Everstake through @Trezor 🔥 A milestone we reached together with our delegators and the Trezor team. Thank you to everyone who keeps choosing Everstake, and to Trezor for the partnership. This is just the start. Stake through Trezor from 0.01 ETH 👇 everstake.com/resources/blog…
3
6
17
2,942
If you’re at @btchelevent today or tomorrow, come by our booth. Let’s talk self-custody, Bitcoin security, privacy, and where Trezor is headed. See you there.
6
8
62
8,675
3M+ Solana Staked in Trezor Suite! 🎉 Secure staking with full self-custody. Powered by @everstake_pool
6
3
28
7,760
Trezor retweeted
Exploring Trezor Safe 7 with @tsusanka 👉 piped.video/watch?v=pPUHiu5o… Two secure elements with unique properties: one NDA-free EAL6+ and, the other, the world’s first open source secure element. How does the Trezor Safe 7 compare to the older models? @joegrand comments.
3
3
20
3,107
Working remote? Your wallet should too. Trezor Safe 7 lives in your pocket, not a desk drawer. Connect it to Trezor Suite on your phone or laptop via Bluetooth and sign transactions from anywhere.
7
6
49
9,465
Clear signing follows you across Ethereum mainnet, L2s, and EVM-compatible sidechains. ✅ Fully open-source ✅ Trusted screen ✅ Zero setup See it. Verify it. Sign with confidence.
15
3
44
9,552
Our third-party e-mail provider has been breached. Please be aware that the email named ‘Critical Security Alert: STM32 Entropy Vulnerability’ is not coming from us, and it’s a phishing attempt. Do not click on any link. We have taken down the domain, and we are investigating the situation, including how the hackers got access to our legit domain.
984
1,376
5,592
3,421,211
Clear Signing translates complex transactions into plain language, so you never approve something you don't understand.
14
6
97
24,480
Smart contract transactions can be complex.  Clear Signing makes them easier to understand. Your Trezor decodes supported EVM transactions and shows the action, tokens, amounts, and destination on its trusted screen. See it. Verify it. Sign with confidence.
25
23
207
61,311
At Trezor, transparency and security are our top priorities. Found a vulnerability? Report it responsibly, get rewarded, and help us fix it before users are put at risk. Learn more about our bug bounty program: trezor.io/other/partner-port…
23
25
209
19,174
Trezor stands firmly behind responsible disclosure. By working together, we can keep raising the bar for security, protect users, and share what we learn to make the whole ecosystem stronger.
📌 AI made finding bugs cheap, but it didn’t make responsible disclosure optional. Finding and exploiting vulnerabilities has never been easier. A few hours of prompting now does what used to take a skilled researcher weeks. Unfortunately, defenders no longer enjoy the asymmetry they relied on. Security is still a cat-and-mouse game, but with many more cats, the user suffers. Which is exactly why the process around disclosure matters more than ever. How it works, and it is not complicated: ➤ A researcher finds a bug and contacts the vendor privately. ➤ The vendor reproduces, acknowledges, and both sides agree on a timeline. 90 days is the common default, more or less depending on severity, capacity to fix... ➤ During that window both sides keep it secret while the vendor fixes and ships. ➤ Once users are protected, both sides publish. The ecosystem learns. The researcher usually gets paid. The issue now is the barrier is so low that anyone can surface a finding with no security background, and some skip straight to the audience: ❗Presenting a reproduction of an already-fixed bug as a live compromise. ❗Full disclosure of a bug that is not fixed yet. ❗"Critical vulnerability found" teasers, dripping details for engagement. Call it what it is: attention farming with someone else's risk. When the bug sits between a user and their funds, this is reckless. Especially in crypto, where there is no chargeback. But the damage doesn't require live funds to be at stake. Manufactured panic causes harm of its own, because it drives people away from self-custody, and that damages the whole ecosystem. So I have three asks: 1️⃣ For users: software and hardware have bugs, always. The single most effective thing you can do is stay updated and follow basic security hygiene. That has never mattered more than today. The time between releases and malicious actors exploiting the vulnerabilities have shrunk dramatically due to LLMs and that one can't afford to be passive and postpone security updates any more 2️⃣ For new researchers with a fresh model and a real, validated finding: welcome, we need you. Use the vendor's disclosure process. That is not bureaucracy. It is the difference between making the ecosystem safer and putting users in the crosshairs for a few likes. Remember that security communication must be accurate and proportionate. State the severity, affected versions, and fix status in the first sentence, not the tenth. 3️⃣ And to everyone building in this industry, vendors and researchers alike: let's make coordinated disclosure the norm we defend out loud, not the fine print. Reward the researchers who do it right. Refuse to amplify the ones who trade user safety for reach. This is how we win, together. Some of the actors already support the initiative. @Ledger @Trezor @FoundationHQ @AnchorWatch @_SEAL_Org and others Spread the message.
20
19
291
38,555
Two days ago, we received an update from our shipping provider, ShipMonk. We're deeply saddened to share the news that the recent data breach affects more customers than originally thought. Another 67,000 customers from the US who ordered between November 2019 and August 2021 were affected, with their full details (name, email, phone number, shipping address, order number) exposed. All affected customers have been emailed directly. If you didn’t receive an email, then you are not affected. Throughout our entire relationship with ShipMonk, we repeatedly requested and received written assurance confirming the deletion of the data, in line with our contract, data policy, and past communications. We are very disappointed that, despite receiving this confirmation, the data was not deleted in their systems. Trezor systems were not compromised, and your device is secure. But please be alert for fake emails, phone calls, fraudulent letters, and potential risks to physical security. NEVER share your wallet backup with anyone or type it into a website. We’re terribly sorry to everyone affected. We take this matter very seriously and are working to ship anonymous delivery ASAP, so you can protect your personal information when placing an order. For more information, visit our blog: trezor.io/blog/news/recent-c…
We have some difficult news to share. Unfortunately, one of our shipping providers has experienced a data breach that exposed sensitive order data. This affects new customers in the US, UK, Sweden, Colombia, Brazil, Italy, and Portugal who received an order within the 90 days prior to August 8th, 2026. The data exposed: - Full names - Shipping addresses - Phone numbers - Email addresses The incident affects 11,742 customers with full exposure (name, email, phone number, shipping address) and 1,947 customers with partial exposure (name, city, email). The breach is limited due to Trezor’s strict 90-day data storage policy (we were also able to negotiate the same terms with fulfillment partners, who follow the same policy). All affected customers have been contacted separately by email. Our systems and devices remain secure, but affected customers could experience an increase in phishing attempts. NEVER enter your wallet backup on a website or share it with anyone, and only check for updates on official Trezor channels. We are deeply sorry to the community and those affected. We are investigating this situation and will post updates on our blog: trezor.io/blog/news/recent-c…
543
520
2,608
1,117,666
Steakhouse Prime ETH vault is now available on @Trezor Suite. Powered by @morpho. Curated by Steakhouse. Available on Trezor.
5
3
26
5,623