Trezor Sounds Phishing Alarm: Avoid Entering Recovery Seeds Online
Trezor's head of security has sounded the alarm on phishing attacks and AI-assisted social engineering threats targeting crypto users.
A recent breach at a third-party logistics partner, ShipMonk, exposed the contact details of 11,742 customers in August 2026. Trezor immediately warned affected users to be vigilant for phishing emails, phone calls, and fake customer support outreach.
The company also highlighted an operation called 'Operation ASTERIX,' which used AI tools to build counterfeit applications mimicking Trezor's software environment. The attackers would query exchange APIs to identify potential victims with significant crypto balances, then direct them to the fake apps.
Trezor emphasized that recovery seeds should never be entered into anything online and that users should only enter their seed phrase on the device itself during a legitimate recovery process. Komarek specifically warned against voice phishing, where attackers impersonate Trezor support staff and ask users to read their seed phrase aloud.