๐Ÿ” Why the CTO of Trezor Almost Got Phished โ€” And What That Means for All of Us
When Shift Happensโ€ข
August 27, 2026

๐Ÿ” Why the CTO of Trezor Almost Got Phished โ€” And What That Means for All of Us

In a moment that should concern anyone holding digital assets, Tomas Susanka, the Chief Technology Officer of Trezor โ€” one of the pioneers in hardware wallet security โ€” found himself on a phishing website. Not during work. Not while distracted by a sophisticated attack. Just tired, shopping online in the evening, clicking what he thought was a legitimate link from Google.

"I was pretty fascinated that this can happen even to me," he admits. "I feel like I'm very good at this because this is what I do for ages."

If the person responsible for securing billions of dollars in Bitcoin can nearly fall victim to a scam, what does that say about the rest of us?

๐Ÿ“‰ The Self-Custody Reality Check

Despite all the "not your keys, not your coins" rhetoric, the hard truth is that only around 2% of crypto holders actually self-custody their assets. The remaining 98% keep their funds on exchanges, relying on third parties to secure their wealth.

Why? Because self-custody is hard.

Susanka, who has spent over a decade building tools to make Bitcoin security accessible, acknowledges this tension directly:

"We really think we live by it here at Trezor: security at the cost of usability comes at the cost of security. If the security is not usable, then it just doesn't work for people."

The challenge isn't just technical โ€” it's psychological. People aren't inherently bad at security because they're stupid or lazy. They're bad at security because asymmetric risks are invisible until they materialize.

"You cross a street, you look around whether there is a car, right?" Susanka explains. "But securing your Bitcoin or crypto is so abstract that people tend to just leave it for later. 'I will buy the hardware wallet next month. I will set up new passwords next week.'"

๐ŸŽฏ The Evolution of Crypto Scams

Forget the "Nigerian prince" emails. Today's attackers are patient, well-funded, and sophisticated.

Modern phishing campaigns combine multiple channels โ€” email, WhatsApp, phone calls โ€” to build trust over weeks. They use fluent English, convincing websites, and even AI-generated voices to impersonate trusted figures. In one recent case during the BTC Prague conference, scammers used deep-fake Microsoft Teams calls with the founder's face and voice, asking victims to download malicious software.

"They can really be patient," Susanka warns. "They can talk to you for weeks and really build the trust and only then attack. That's something that has changed a lot โ€” those big groups have proper funding and expertise."

Even more troubling: AI has dramatically lowered the barrier to entry for scammers. Voice cloning now requires just two minutes of audio. Deep-fake video can be generated in real-time. And the attackers are getting better at targeting moments of weakness โ€” late at night, when you're tired, when your guard is down.

๐Ÿ’ก The Asymmetric Risk Problem

Why do smart people still fall for scams? Why do successful entrepreneurs lose hundreds of thousands of dollars to obvious phishing attacks?

Susanka believes it comes down to asymmetric risk โ€” situations where the probability feels low, but the impact is catastrophic. Humans are notoriously bad at calculating these scenarios.

"By nature, people are not very good at that," he says. "We tend to believe what we have in our surroundings โ€” our friends, our family. Until you somehow prove the risk is real, people are automatically ignorant to probability statistics."

This extends beyond scams to the very concept of self-custody itself. The fiat banking system has trained people to trust third parties. Self-custody requires a complete mental shift โ€” one that many users simply aren't willing or able to make.

๐Ÿ›ก๏ธ The Five Layers of Defense

So how does Trezor think about security in a world where everything is hackable given infinite time and money?

Susanka walks through the defense-in-depth strategy built into the Trezor Safe 7:

  1. Physical theft required โ€” An attacker must physically steal the device
  2. Disassembly without damage โ€” They must take it apart without destroying anything
  3. Three-chip architecture โ€” The device uses three separate chips (a generic chip, an Infineon secure element, and a Tropic Square secure element) that together store the private keys. Breaking one chip gets you nowhere.
  4. PIN protection โ€” Even with access to all three chips, you still need to crack the user's PIN
  5. Passphrase option โ€” For paranoid users, an additional passphrase adds yet another layer

"If you break just one, you still don't get to the private keys," Susanka explains. "If you hack two, you still don't really get anywhere. And by the way, on those chips there is no known remote exploit."

The philosophy? Give users enough time to notice their device is missing and move their funds before an attacker can break through all five layers.

โš›๏ธ The Quantum Computing Question

Should the crypto industry be worried about quantum computing?

Susanka's answer is nuanced. He doesn't expect a "relevant quantum computer" to emerge in the next five to ten years. But he takes the threat seriously โ€” not because the probability is high, but because the impact would be catastrophic.

"If there's even a tiny chance โ€” like really tiny โ€” that someone can build a relevant quantum computer that could endanger Bitcoin, then I think we should take the threat seriously."

The good news? The industry is starting to pay attention. Two years ago, quantum risk was dismissed as FUD. Today, companies like Blockstream, Coinbase, and Trezor are actively researching solutions. Trezor's Safe 7 includes "quantum-ready" features that allow firmware updates to be delivered in a quantum-safe manner.

The challenge? Bitcoin's greatest strength โ€” decentralization โ€” is also its biggest vulnerability here. Unlike Microsoft, which can simply mandate a quantum-resistant upgrade, Bitcoin requires community consensus. And as anyone who remembers the block size wars can attest, consensus takes time.

๐Ÿ”‘ Practical Security Advice

Susanka offers several concrete recommendations for anyone holding crypto:

General Rules:

  • Stay vigilant and suspicious โ€” If it's too good to be true, it probably is
  • Never download or install files from unexpected sources, even from people you "know"
  • Use browser-based tools instead of downloading software whenever possible
  • Be the one to send meeting links โ€” never join calls via links sent to you
  • Don't answer calls from unknown numbers โ€” use text messages to verify legitimacy first
  • Be aware of your surroundings โ€” especially when traveling or in public spaces

For Crypto Specifically:

  • Consider a hardware wallet once your holdings reach twice the cost of the device
  • Aim for an 80/20 split between self-custody and exchanges (adjusting based on your use case)
  • Check your backup โ€” know where it is, verify it's correct, and ensure it's stored securely
  • For large amounts, consider splitting across two hardware wallet vendors for additional redundancy
  • Never enter your seed phrase into any website or digital device

๐Ÿค” The Inheritance Problem

One of the biggest unsolved challenges in self-custody? Inheritance.

Traditional banking has clear processes for transferring assets when someone dies. Self-custody? Not so much. If you're the only person who knows your seed phrase and something happens to you, those funds are gone forever.

Susanka acknowledges this is "really tough to do in a self-custodial, decentralized manner."

"You know, there are always ideas like 'let's put part of your recovery seed in your parents' Google Drive,' but we don't want to be dependent on Google. We don't want to be dependent on Apple. And when you really lay out all these conditions, it's really tough to bring something up."

For now, solutions like ETFs offer a pragmatic compromise โ€” they sacrifice some sovereignty and privacy, but provide clear inheritance mechanisms through traditional financial systems.

๐Ÿ“Š The Market Reality

When asked about the current bear market sentiment and whether people should still care about Bitcoin, Susanka's response cuts to the core:

"The story, the narrative behind Bitcoin hasn't changed. Now the price dropped and everyone is interested in AI โ€” no one really cares about Bitcoin anymore. But the reason why Bitcoin emerged and the reason why Bitcoin exists, that's something that still is something we need."

Fiat currencies remain unbacked. The gold standard is gone. People still need ways to preserve wealth outside traditional financial systems. These fundamentals haven't changed, regardless of whether Bitcoin is trading at all-time highs or 50% down.

"It's up and down," he says simply. "I really feel like next year it's going to be completely different."

โœ… The Bottom Line

The crypto industry has oversold the idea that self-custody is easy. It's not. But it's also not as hard as people think.

The real challenge isn't technical โ€” it's behavioral. It's the tired evening when you click the first Google result. It's the exciting opportunity that seems too good to be true. It's the backup you mean to check "next week."

Security isn't about being paranoid. It's about being prepared.

As Susanka puts it: "It's fine if you decide not to wear a helmet on a scooter, I suppose. But you need to know what the risks are. The education part is vital for the risk part."

The same applies to crypto. You don't have to self-custody everything. But you should at least understand what you're giving up when you don't.

Because in a world where even the experts can almost fall for phishing scams, awareness might be the most valuable security tool we have.

More from When Shift Happens

๐Ÿ”ฅ Wall Street Meets DeFi: The Zero-Fee RWA Revolution
Summary

Why Traditional Brokerages Are Quietly Panicking About Onchain Trading

When Shift Happensโ€ข
2d ago

๐Ÿ“Š The Future of Trading Is Here โ€” And It Costs NothingA new wave of onchain trading infrastructure is fundamentally cha...

WatchRead more
๐ŸŽฏ The Uncomfortable Truth About 'Making It' in Crypto
Summary

Why Bitcoin Remains the Answer (Even When Nobody Wants to Hear It)

When Shift Happensโ€ข
3d ago

๐Ÿ“‰ The Hard Reality: Most Won't Make ItThe crypto industry loves its aspirational narratives โ€” the idea that passion, pe...

WatchRead more
๐ŸŽฏ The Death of Get-Rich-Quick Crypto (And What Actually Works Now)
Summary

Lessons From 2022: Why Smart Crypto Investors Are Getting Boring

When Shift Happensโ€ข
Sep 4

๐Ÿ“‰ The Alt Season Fantasy Is DeadThe crypto landscape has fundamentally shifted. The wild, lottery-like gains that defin...

WatchRead more
๐Ÿฆ The $100M User Race: Why Crypto's Neo-Bank Battle Is Just Getting Started
Summary

Athena Labs CEO Guy Young on Building the DeFi Super App โ€” And Why the Real Comp

When Shift Happensโ€ข
Sep 2

๐Ÿ’ต The One Product That Can Hit 100 Million Users In a market saturated with perps, meme coins, and layer-one competiti...

WatchRead more
๐Ÿ” The $1.5B Hack That Changed Custody Forever โ€” Why Seed Phrases Are Already Obsolete
Summary

The End of Seed Phrases: How Institutional-Grade Security is Finally Coming to R

When Shift Happensโ€ข
Sep 1

๐Ÿ’ผ From Quant Trading to Building a Billion-Dollar Custody EmpireDmitry, CEO and co-founder of BRON, has spent a decade ...

WatchRead more
๐ŸŽฏ The Wall Street Myth: Why Your Zip Code Matters More Than Your Degree
Summary

Breaking Down the Finance Industry's Biggest Lies โ€” From Morgan Stanley Partner

When Shift Happensโ€ข
Aug 31

๐Ÿ“ The Zip Code AdvantageThe finance industry operates on a myth that few dare to acknowledge openly: success on Wall St...

WatchRead more