This was the message that I got today from scammers. I thought there was no link on the email until I click on the Trezor at the top and at the bottom of the email which are both same fake links.
What made me first felt suspicious about it is that I think Trezor will only advise people to use passphrase, but the email is about Trezor now adding feature to passphrase that people can use to make it longer. Which means the email can deceive some people to try locate the link and click on it which will take them to the fake Trezor site which you can see its link on the third image.
I also think Trezor users supposed to have known all these and avoid it. There have been more than 50 emails that I have received before which is enough to let Trezor users always verify before proceeding.
This is the official Trezor website:
https://trezor.ioAbout the Coldcard vulnerability
Yes it is good to use long passphrase to avoid the hack if something like it happened to Trezor, but Trezor is still safe and it is open source, but adding passphrase and send your coins to the address generated is very good and make your wallet more secure, but creating long passphrase has been on reputable bitcoin wallet before and not need any update to make it possible.