‘Your Wallet Doesn’t Decide When You Need Your Backup’: Trezor Analyst on the Fake App Problem

fiverr
Blockonomics


Fake wallet apps that ask for a seed phrase have been around for years, and several campaigns this year show they still work.

We asked Lucien Bourdon, Bitcoin Analyst at Trezor, to go past the usual “don’t share your seed” advice and explain why these scams succeed and what gives them away.

U.Today: A lot of advice out there says “never share your seed phrase.” Why isn’t that advice stopping these scams?

coinbase

SEC Proposes New Crypto Custody Framework


Hyperliquid (HYPE), Stellar (XLM), Zcash (ZEC) and Ethereum (ETH) Price Analysis for October 2: Investors Take Profits

Lucien Bourdon: Most people wouldn’t type their seed phrase into an email or read it out over the phone. They know better than that. What often gets them is a fake app, sent to them through something like a fake support email that gives a reason for using it, such as a security update or a wallet recovery. The fake app shows a form asking for the seed phrase, and the email’s urgency pushes them to fill it in before they notice something is wrong.

The urgency usually comes from fear. An email says your device is affected by a vulnerability and you need to recover your wallet to stay safe. Sometimes it works the other way, with an offer. There are fake apps and pages promising an airdrop, where you enter your seed phrase to claim it.

U.T.: How do these fake apps reach people?

L.B.: All of these are from this year, and there’s no sign the people behind them are connected.

In August, people searching “Trezor wallet” on Google clicked the sponsored result at the top and landed on a fake Trezor Suite, built on Google Sites, that asked for their seed phrase. One address alone took in about 24 BTC across roughly 80 deposits, all visible to anyone on a block explorer.

In April, a fake Ledger Live app got onto Apple’s Mac App Store. About 50 people downloaded it and entered their seed phrases, and around $9.5 million was gone before Apple took the listing down.

In February, people received printed letters branded as hardware wallet companies, warning of a fake authentication deadline. A QR code on each letter led to a copy of the wallet’s recovery screen asking for 12, 20 or 24 words.

The method changes each time, but the last step is always a screen asking for the seed phrase.

U.T.: What does a fake wallet app actually look like in 2026?

L.B.: It looks exactly like the real one: same logo, same layout, same screens, often the same name in search results or an app store. That has been true for years. What’s changed is that AI tools have made convincing copies faster and cheaper to build, so there are more of them and fewer obvious mistakes to catch.

And if your computer is infected, malware can show a fake page inside any app, including a genuine wallet app. So how an app looks on your computer or phone tells you nothing about whether it’s genuine.

Either way, the giveaway is what it asks for: a form with numbered boxes for 12, 20 or 24 words, asking you to type your seed phrase into the computer or phone. If you use a hardware wallet, that request is the red flag on its own.

U.T.: How does the advice differ between a hardware wallet and a software wallet?

L.B.: With a hardware wallet, your seed phrase, or wallet backup as we call it, only ever goes into the hardware wallet itself. The device generates it, and if you need to recover, you enter it on the device’s own touchscreen or buttons. It never needs to be typed into a computer or phone, so there’s nothing for malware or a fake app to intercept. That offline security is the main reason to own a hardware wallet.

So if your computer or phone asks you to type in your backup, it’s a scam, even if it looks exactly like Trezor Suite. The backup goes into the device and nowhere else.

Software wallets like Trust Wallet or MetaMask work differently. They run on your computer or phone and keep the keys there, so recovering one means typing the seed phrase into that device. For a software wallet, a recovery screen asking for your seed phrase can be genuine. For a hardware wallet, it never is.

U.T.: What is a seed phrase actually for, and when would someone legitimately need to use it?

L.B.: Its only job is restoring your wallet, onto a new device or after yours is lost or stops working. No update ever needs it, including security patches, whether you use a hardware wallet or a software one.

Recovery only ever starts with you. You’ve got a new device, or you’re restoring a wallet, and you go and get your backup yourself. Nothing else decides that for you. If an app or message on a computer or phone brings it up first, it’s a scam, whatever reason it gives.

U.T.: What would Trezor actually ask you, compared with what a scammer would ask?

L.B.: We do send legitimate messages, such as order updates or security notices. They’re rarely urgent, and they never ask for your seed phrase or any other private information. If something did need fast action, you’d also see it on trezor.io, on our official social channels, and likely in the press. Our support team never contacts you first.

Scammers usually do contact you first, and their message always comes with urgency. What they want is your seed phrase typed into an app, funds sent to an address they control, or a transaction signed on your device.

If you’re not sure whether a message is from us, don’t use any link or phone number in it. Go to trezor.io yourself and contact support from there.

U.T.: If someone remembers one thing from this, what should it be?

L.B.: Your seed phrase or wallet backup exists to get your wallet back, and only when you’re the one who went looking for it. Anything else asking for it is a scam, no matter how convincing it looks.



Source link

Changelly

Be the first to comment

Leave a Reply

Your email address will not be published.


*