{
  "object": "jepeta_content_article",
  "schemaVersion": "1.0.0",
  "id": "article.trezor-clear-signing-vs-phishing-2026",
  "contentType": "evergreen_guide",
  "title": "Trezor Clear Signing: What You Can Verify on the Device, and What You Still Can't",
  "slug": "trezor-clear-signing-vs-phishing-2026",
  "category": "security",
  "intent": "Understand which Trezor Clear Signing protections apply to real EVM transactions and which phishing risks remain outside the device.",
  "directAnswer": "Trezor Clear Signing decodes supported EVM smart-contract calls and shows the action, token, amount and destination on the trusted device screen. It relies on ERC-7730 registry support and compatible firmware, and it cannot protect a recovery phrase entered into a phishing application.",
  "format": "markdown",
  "seoTitle": "Trezor Clear Signing in 2026: Support, Limits and Phishing",
  "metaDescription": "Trezor Clear Signing makes supported DeFi transactions readable on-device. Check model, firmware and contract coverage, and the phishing risks it cannot stop.",
  "sections": [
    {
      "heading": "Overview and what we verified",
      "paragraphs": [
        "*Source review: October 9, 2026. This is a documentation-based explanation, not a hands-on hardware test.*\n\nA hardware wallet can keep a signing key off an internet-connected computer. That does not automatically tell you what a smart contract is asking the key to authorize. Trezor's **Clear Signing**, announced on September 7, 2026, tackles that second problem: it shows readable details of **supported** smart-contract interactions on the device screen. The word *supported* is doing important work here.\n\nClear Signing also has a different threat boundary from recovery-phrase phishing. Trezor's September incident involving its external email provider demonstrates why the distinction matters."
      ]
    },
    {
      "heading": "Two different questions before you approve",
      "paragraphs": [
        "A secure signing flow needs to answer both questions:\n\n1. Is the private key protected from the computer or website making the request?\n2. Can the person approving the transaction understand what the device is actually signing?\n\nA traditional hardware wallet can perform the first job while showing opaque calldata for the second. A compromised or misleading website might describe an innocent-looking action while requesting something different. With **a supported contract**, Clear Signing decodes the call and displays its action, tokens, amounts and relevant addresses on the trusted device display. You can compare those details against your own intent rather than accepting the browser's summary.\n\nThis does **not** mean the device makes a judgment that a token is safe, or that the transaction is economically sensible. It means the device offers a better explanation of the instruction presented for approval. [Trezor's announcement](https://trezor.io/blog/news/clear-signing-comes-to-trezor-our-flagship-security-feature-of-2026) and [technical guide](https://trezor.io/guides/sending-receiving-staking-funds/interacting-with-smart-contracts/clear-signing-on-trezor) describe that specific capability."
      ]
    },
    {
      "heading": "What is covered, and what falls back to blind signing?",
      "paragraphs": [
        "| Question | Documented answer |\n| --- | --- |\n| Which networks? | Ethereum and supported EVM-compatible networks, including Base. |\n| Which contracts? | Contracts with supported descriptors in the ERC-7730 registry. Coverage is **not universal**. |\n| Which devices? | Trezor Model T, Safe 3, Safe 5 and Safe 7 with Universal firmware 2.12.4 or later, according to Trezor's guide. |\n| Which connections? | Supported flows through Trezor Suite, WalletConnect and Trezor Connect. |\n| What if the contract is missing from the registry? | The wallet falls back to the usual blind-signing warning. |\n| Does it verify whether the asset is a scam or a good investment? | No. Readable instructions are not a token-risk assessment. |\n\nIf the device does not display understandable details, do not assume the browser's preview has been independently verified. Check that your model, firmware, network and contract are supported before treating a transaction as clear-signed."
      ]
    },
    {
      "heading": "Why Trezor's September email incident is relevant",
      "paragraphs": [
        "On September 10, Trezor disclosed an incident at Brevo, its third-party marketing-email provider. In an update dated September 17, Trezor said **347,149 marketing email contacts were exported**. A malicious message linked to an application asking people to enter their wallet backup. Trezor stated that its own device and wallet systems were not breached.\n\nThat account is [Trezor's published description](https://trezor.io/blog/news/security-incident-at-brevo-our-third-party-email-provider), not an independent forensic finding by Jepeta.\n\nThe incident illustrates a separate attack path. Clear Signing helps people inspect *supported transaction instructions*. It cannot protect a wallet if someone enters the recovery phrase into a phishing application. A perfectly readable approval screen cannot undo disclosure of the secret used to recover the wallet."
      ]
    },
    {
      "heading": "A practical check before the next DeFi transaction",
      "paragraphs": [
        "- **Check what is actually on the device.** Match the requested action, token, amount and destination to what you intended. If a relevant field is missing or unexpected, stop.\n- **Check coverage.** A familiar wallet model is not enough; support also depends on firmware and the contract descriptor.\n- **Review allowances separately.** An understandable approval may still grant broad or long-lived permissions. See [Jepeta's guide to token-approval risk](https://jepeta.dev/articles/token-approval-risk-before-swap/) for that separate issue.\n- **Keep the wallet backup offline.** Do not enter recovery words into an application reached from an email or chat link. Follow your wallet provider's official recovery process only.\n- **Treat the feature as one control.** Contract code, dApp authenticity, liquidity and the user's intended action remain independent questions."
      ]
    },
    {
      "heading": "Is Clear Signing a reason to choose a Trezor?",
      "paragraphs": [
        "For someone who regularly signs EVM contract calls, visibility on the device may be a meaningful purchase criterion. Someone who rarely uses DeFi may give greater weight to supported assets, screen ergonomics, recovery options and long-term firmware maintenance. There is no universal winner, and this article does not compare devices through hands-on testing.\n\n**Jepeta's assessment:** Clear Signing narrows the gap between protecting a key and understanding an instruction. It does not close the gaps created by unsupported contracts, deceptive applications or recovery-phrase theft."
      ]
    },
    {
      "heading": "Sources and limitations",
      "paragraphs": [
        "(https://trezor.io/blog/news/clear-signing-comes-to-trezor-our-flagship-security-feature-of-2026).\n(https://trezor.io/guides/sending-receiving-staking-funds/interacting-with-smart-contracts/clear-signing-on-trezor).\n(https://trezor.io/blog/news/security-incident-at-brevo-our-third-party-email-provider).\n\nThis article compares published primary-source documentation. It does not certify Trezor hardware, audit the ERC-7730 registry, reproduce the Brevo incident investigation, or provide investment advice. No affiliate relationship or paid placement is included in this draft."
      ]
    }
  ],
  "sources": [
    {
      "id": "trezor_announcement",
      "label": "Trezor: Clear Signing comes to Trezor (September 7, 2026)",
      "url": "https://trezor.io/blog/news/clear-signing-comes-to-trezor-our-flagship-security-feature-of-2026",
      "publishedAt": "2026-09-07T00:00:00Z",
      "sourceType": "primary",
      "verifiedAt": "2026-10-09T05:16:43.493Z"
    },
    {
      "id": "trezor_guide",
      "label": "Trezor: Clear Signing technical guide",
      "url": "https://trezor.io/guides/sending-receiving-staking-funds/interacting-with-smart-contracts/clear-signing-on-trezor",
      "publishedAt": null,
      "sourceType": "primary",
      "verifiedAt": "2026-10-09T05:16:43.493Z"
    },
    {
      "id": "trezor_brevo",
      "label": "Trezor: Security incident at Brevo (September 10; update September 17)",
      "url": "https://trezor.io/blog/news/security-incident-at-brevo-our-third-party-email-provider",
      "publishedAt": "2026-09-10T00:00:00Z",
      "sourceType": "primary",
      "verifiedAt": "2026-10-09T05:16:43.493Z"
    }
  ],
  "sourceDates": [
    {
      "sourceId": "trezor_announcement",
      "publishedAt": "2026-09-07T00:00:00Z",
      "verifiedAt": "2026-10-09T05:16:43.493Z"
    },
    {
      "sourceId": "trezor_guide",
      "publishedAt": null,
      "verifiedAt": "2026-10-09T05:16:43.493Z"
    },
    {
      "sourceId": "trezor_brevo",
      "publishedAt": "2026-09-10T00:00:00Z",
      "verifiedAt": "2026-10-09T05:16:43.493Z"
    }
  ],
  "originalEvidence": [
    {
      "type": "structured_comparison",
      "description": "Jepeta compared time-stamped primary documentation, feature limitations and decision criteria, without claiming a hands-on test or independently certifying vendor results.",
      "url": "https://trezor.io/blog/news/clear-signing-comes-to-trezor-our-flagship-security-feature-of-2026",
      "observedAt": "2026-10-09T05:16:43.493Z"
    }
  ],
  "datePublished": "2026-10-09T05:16:43.493Z",
  "dateModified": "2026-10-09T05:16:43.493Z",
  "reviewedAt": "2026-10-09T05:16:43.493Z",
  "affiliate": {
    "enabled": false,
    "partnerId": null,
    "linkId": null,
    "disclosureRequired": false,
    "rel": null
  },
  "disclosure": null,
  "internalLinks": [
    "/articles/token-approval-risk-before-swap/",
    "/guides/",
    "/methodology.html"
  ],
  "telegramCohort": {
    "surface": "article",
    "cohortId": "article"
  },
  "quality": {
    "decision": "publish",
    "citabilityScore": 100,
    "reviewedAt": "2026-10-09T05:16:43.493Z",
    "policyVersion": "1.0.0"
  },
  "canonicalUrl": "https://jepeta.dev/articles/trezor-clear-signing-vs-phishing-2026/",
  "jsonUrl": "https://jepeta.dev/articles/trezor-clear-signing-vs-phishing-2026/index.json"
}
