Crypto▼ Bearish

Trezor Warns of AI Clones and Phishing After ShipMonk Breach

By AlphaScala Research DeskSource reporting: Crypto BriefingEditorial standards2 views
Trezor Warns of AI Clones and Phishing After ShipMonk Breach

Trezor's security chief warns of AI-cloned apps and vishing after the ShipMonk breach exposed 11,742 customers. Trezor hardware wasn't compromised.

Hardware wallet maker Trezor is warning users about a pair of threats its head of security says now define the risk profile for holding crypto yourself: phishing and AI-assisted social engineering. The warning follows a data breach at a logistics partner and an operation that used AI to build clones of Trezor's software.

Jan Komarek, Trezor's head of security, said the threats are not abstract. ShipMonk, the fulfillment company that handles Trezor's logistics, suffered a data breach in August 2026 that affected 13,689 customers. Of those, 11,742 had their full information exposed, including names and contact details.

Trezor said the hardware itself was not compromised. The company urged affected customers to watch for phishing emails and fraudulent phone calls in the weeks after the breach.

Separately, security firm Rapid7 detailed a campaign it named "Operation ASTERIX." The attackers built counterfeit applications that mimicked Trezor's software environment. They first queried exchange APIs to identify users likely to hold meaningful crypto balances, then directed those users toward the fake apps. Once inside, the app prompted for a recovery seed and forwarded the input to the attackers over Telegram.

A recovery seed is the sequence of 12 or 24 words that acts as the master key to a wallet. Anyone with the seed controls everything in it.

Vishing, or voice phishing, is part of the same toolkit. Attackers call users, impersonating Trezor support, and walk them through a fake "security procedure" that ends with the user reading the seed aloud. Komarek flagged vishing as a growing concern, saying Trezor will never call a user and ask for a recovery seed under any circumstances.

The practical rules stay short. Recovery seeds live in one place: a physical backup, offline, entered only on the Trezor device during a legitimate recovery. Email drafts and notes apps are not backups. Neither is a Telegram bot that promises to "verify" a wallet.

Komarek's warnings land at a time when phishing incidents against crypto users have been climbing steadily, a trend documented across multiple security firms between 2025 and 2026.

How this story was producedLast reviewed Aug 30, 2026

Drafted by a large language model from the source reporting linked above, then screened by automated publishing checks. It is not read by a journalist before publication. Some articles cite our Alpha Score. Verify prices and figures against the original source. Educational coverage, not personalized advice.

Editorial Policy·Report a correction·Risk Disclaimer

Related Tools & Research