Hardware wallet maker Trezor is sounding the alarm on what its head of security, Jan Komarek, describes as the most serious threats facing crypto users today: phishing attacks and AI-assisted social engineering. The warning is not abstract. A breach at a third-party logistics partner and a documented operation using artificial intelligence to clone Trezor’s ecosystem have given the threat a concrete shape.
Komarek’s core message is simple enough to fit on a sticky note: never type your seed phrase into anything online, ever.
When a shipping partner becomes a security liability
In August 2026, ShipMonk, a fulfillment and shipping company that handles logistics for Trezor, suffered a data breach affecting 13,689 customers. Of those, 11,742 had their full information exposed, including names and contact details.
Trezor issued warnings immediately after the breach became known, cautioning affected users to be on heightened alert for phishing emails, fraudulent phone calls, and fake customer support outreach. The hardware itself was not compromised.
Operation ASTERIX and the AI-powered phishing playbook
Separately, cybersecurity firm Rapid7 detailed an operation it named “Operation ASTERIX,” which used AI tools to build counterfeit applications that mimicked Trezor’s software environment. The attack chain worked in stages. First, attackers identified potential victims by querying exchange APIs, filtering for users likely to hold meaningful crypto balances. Then they directed those users toward the fake applications. Once inside, the app prompted users to enter their recovery seeds, funneling that input directly to the attackers via Telegram.
A recovery seed is a sequence of words, typically 12 or 24, that functions as the master key to a crypto wallet. Anyone who has it owns everything in that wallet.
Vishing, voice phishing, is part of this toolkit too. Attackers call users directly, impersonating Trezor support staff, and walk them through a fake “security procedure” that ends with the user reading their seed phrase aloud. Komarek specifically flagged this vector as a growing concern, noting that Trezor will never call a user and ask for a recovery seed under any circumstances.
What this means for self-custody users
The Trezor device itself has not been compromised in any of these incidents. For users, the practical implications come down to a short list of non-negotiable habits. Recovery seeds belong in one place: a physical backup, offline, entered only on the Trezor device itself during a legitimate recovery. Not in an email draft, not in a notes app, not in a Telegram bot that promises to “verify” a wallet.
Komarek’s warnings arrive during a period when phishing incidents against crypto users have been climbing steadily, a trend documented across multiple security firms tracking the space between 2025 and 2026.
Disclosure: This article was edited by Editorial Team. For more information on how we create and review content, see our Editorial Policy.

1 hour ago
18









English (US) ·