A seller on a cybercrime forum is offering a tool called AntiTrezor, and the pitch is about as blunt as it gets: it injects a fake interface into Trezor Suite and tricks users into revealing their seed phrase.
According to the seller's claims, the tool can steal recovery phrases as they are typed, block outgoing transfers so the victim cannot move funds out of harm's way, and ship the whole wallet dossier to an operator panel in real time.
The nasty part is the attack surface. There is no remote exploit and no broken cryptography here - the tool simply shows the victim a convincing copy of software they already trust. If it works as advertised, the last line of defense is whether the user notices something is off before typing twelve or twenty-four words into a box that should never ask for them.
That is why the old advice still wins: download wallet software only from official sources, and treat any prompt for your recovery phrase as hostile by default. No legitimate update, support agent or synchronization screen will ever need it.
The same reflex protects you on messaging apps. At Vulpine, your recovery phrase is generated on your device and shown to you exactly once - no website, desktop app or support screen will ever ask you to type it somewhere, and anything that does is AntiTrezor's cousin.