Hardware wallet maker Trezor is warning of escalating security threats targeting crypto users, with the company's head of security Jan Komarek highlighting phishing attacks and AI-assisted social engineering as primary concerns. The warnings follow concrete incidents including a data breach at a third-party logistics partner and a documented operation using artificial intelligence to create counterfeit Trezor applications.
In August 2026, ShipMonk, a fulfillment company handling logistics for Trezor, suffered a data breach affecting 13,689 customers. The breach exposed full information for 11,742 customers, including names and contact details. Trezor issued immediate warnings to affected users about potential phishing emails, fraudulent calls, and fake customer support attempts, though the hardware devices themselves were not compromised.
AI-Powered Counterfeit Applications
Cybersecurity firm Rapid7 documented an operation it named "Operation ASTERIX," which used artificial intelligence tools to build fake applications mimicking Trezor's software environment. The attack operated in stages: attackers first identified potential targets by querying exchange APIs to find users likely holding significant cryptocurrency, then directed those users to the fraudulent applications. Once users opened the fake app, they were prompted to enter their recovery seeds, which were sent to attackers via Telegram.
A recovery seed—typically a sequence of 12 or 24 words—functions as a master key to a cryptocurrency wallet. Anyone possessing it can access all funds in that wallet.
Voice Phishing and Impersonation
Voice phishing, or vishing, has become part of attackers' toolkit. Komarek flagged this vector as an increasing concern, noting that attackers impersonate Trezor support staff and guide users through fake security procedures designed to elicit their seed phrases. Trezor has stated it will never call users requesting recovery seeds under any circumstances.
User Security Practices
Komarek emphasized that recovery seeds should exist only as physical backups stored offline and entered solely on Trezor devices during legitimate recovery operations. He cautioned against storing seeds in email drafts, notes applications, or messaging services that claim to verify wallets.
These warnings come amid a documented trend of rising phishing incidents against cryptocurrency users tracked by multiple security firms between 2025 and 2026.


