Hardware wallet maker Trezor is sounding the alarm on what its head of security, Jan Komarek, describes as the most serious threats facing crypto users today: phishing attacks and AI-assisted social engineering. The warning is not abstract. A breach at a third-party logistics partner and a documented operation using artificial intelligence to clone Trezor’s ecosystem have given the threat a concrete shape.

Komarek’s core message is simple enough to fit on a sticky note: never type your seed phrase into anything online, ever.

When a shipping partner becomes a security liability

In August 2026, ShipMonk, a fulfillment and shipping company that handles logistics for Trezor, suffered a data breach affecting 13,689 customers. Of those, 11,742 had their full information exposed, including names and contact details.

Trezor issued warnings immediately after the breach became known, cautioning affected users to be on heightened alert for phishing emails, fraudulent phone calls, and fake customer support outreach. The hardware itself was not compromised.