šŸ” Why the CTO of Trezor Almost Got Phished — And What That Means for All of Us
When Shift Happens•
August 27, 2026

šŸ” Why the CTO of Trezor Almost Got Phished — And What That Means for All of Us

In a moment that should concern anyone holding digital assets, Tomas Susanka, the Chief Technology Officer of Trezor — one of the pioneers in hardware wallet security — found himself on a phishing website. Not during work. Not while distracted by a sophisticated attack. Just tired, shopping online in the evening, clicking what he thought was a legitimate link from Google.

"I was pretty fascinated that this can happen even to me," he admits. "I feel like I'm very good at this because this is what I do for ages."

If the person responsible for securing billions of dollars in Bitcoin can nearly fall victim to a scam, what does that say about the rest of us?

šŸ“‰ The Self-Custody Reality Check

Despite all the "not your keys, not your coins" rhetoric, the hard truth is that only around 2% of crypto holders actually self-custody their assets. The remaining 98% keep their funds on exchanges, relying on third parties to secure their wealth.

Why? Because self-custody is hard.

Susanka, who has spent over a decade building tools to make Bitcoin security accessible, acknowledges this tension directly:

"We really think we live by it here at Trezor: security at the cost of usability comes at the cost of security. If the security is not usable, then it just doesn't work for people."

The challenge isn't just technical — it's psychological. People aren't inherently bad at security because they're stupid or lazy. They're bad at security because asymmetric risks are invisible until they materialize.

"You cross a street, you look around whether there is a car, right?" Susanka explains. "But securing your Bitcoin or crypto is so abstract that people tend to just leave it for later. 'I will buy the hardware wallet next month. I will set up new passwords next week.'"

šŸŽÆ The Evolution of Crypto Scams

Forget the "Nigerian prince" emails. Today's attackers are patient, well-funded, and sophisticated.

Modern phishing campaigns combine multiple channels — email, WhatsApp, phone calls — to build trust over weeks. They use fluent English, convincing websites, and even AI-generated voices to impersonate trusted figures. In one recent case during the BTC Prague conference, scammers used deep-fake Microsoft Teams calls with the founder's face and voice, asking victims to download malicious software.

"They can really be patient," Susanka warns. "They can talk to you for weeks and really build the trust and only then attack. That's something that has changed a lot — those big groups have proper funding and expertise."

Even more troubling: AI has dramatically lowered the barrier to entry for scammers. Voice cloning now requires just two minutes of audio. Deep-fake video can be generated in real-time. And the attackers are getting better at targeting moments of weakness — late at night, when you're tired, when your guard is down.

šŸ’” The Asymmetric Risk Problem

Why do smart people still fall for scams? Why do successful entrepreneurs lose hundreds of thousands of dollars to obvious phishing attacks?

Susanka believes it comes down to asymmetric risk — situations where the probability feels low, but the impact is catastrophic. Humans are notoriously bad at calculating these scenarios.

"By nature, people are not very good at that," he says. "We tend to believe what we have in our surroundings — our friends, our family. Until you somehow prove the risk is real, people are automatically ignorant to probability statistics."

This extends beyond scams to the very concept of self-custody itself. The fiat banking system has trained people to trust third parties. Self-custody requires a complete mental shift — one that many users simply aren't willing or able to make.

šŸ›”ļø The Five Layers of Defense

So how does Trezor think about security in a world where everything is hackable given infinite time and money?

Susanka walks through the defense-in-depth strategy built into the Trezor Safe 7:

  1. Physical theft required — An attacker must physically steal the device
  2. Disassembly without damage — They must take it apart without destroying anything
  3. Three-chip architecture — The device uses three separate chips (a generic chip, an Infineon secure element, and a Tropic Square secure element) that together store the private keys. Breaking one chip gets you nowhere.
  4. PIN protection — Even with access to all three chips, you still need to crack the user's PIN
  5. Passphrase option — For paranoid users, an additional passphrase adds yet another layer

"If you break just one, you still don't get to the private keys," Susanka explains. "If you hack two, you still don't really get anywhere. And by the way, on those chips there is no known remote exploit."

The philosophy? Give users enough time to notice their device is missing and move their funds before an attacker can break through all five layers.

āš›ļø The Quantum Computing Question

Should the crypto industry be worried about quantum computing?

Susanka's answer is nuanced. He doesn't expect a "relevant quantum computer" to emerge in the next five to ten years. But he takes the threat seriously — not because the probability is high, but because the impact would be catastrophic.

"If there's even a tiny chance — like really tiny — that someone can build a relevant quantum computer that could endanger Bitcoin, then I think we should take the threat seriously."

The good news? The industry is starting to pay attention. Two years ago, quantum risk was dismissed as FUD. Today, companies like Blockstream, Coinbase, and Trezor are actively researching solutions. Trezor's Safe 7 includes "quantum-ready" features that allow firmware updates to be delivered in a quantum-safe manner.

The challenge? Bitcoin's greatest strength — decentralization — is also its biggest vulnerability here. Unlike Microsoft, which can simply mandate a quantum-resistant upgrade, Bitcoin requires community consensus. And as anyone who remembers the block size wars can attest, consensus takes time.

šŸ”‘ Practical Security Advice

Susanka offers several concrete recommendations for anyone holding crypto:

General Rules:

  • Stay vigilant and suspicious — If it's too good to be true, it probably is
  • Never download or install files from unexpected sources, even from people you "know"
  • Use browser-based tools instead of downloading software whenever possible
  • Be the one to send meeting links — never join calls via links sent to you
  • Don't answer calls from unknown numbers — use text messages to verify legitimacy first
  • Be aware of your surroundings — especially when traveling or in public spaces

For Crypto Specifically:

  • Consider a hardware wallet once your holdings reach twice the cost of the device
  • Aim for an 80/20 split between self-custody and exchanges (adjusting based on your use case)
  • Check your backup — know where it is, verify it's correct, and ensure it's stored securely
  • For large amounts, consider splitting across two hardware wallet vendors for additional redundancy
  • Never enter your seed phrase into any website or digital device

šŸ¤” The Inheritance Problem

One of the biggest unsolved challenges in self-custody? Inheritance.

Traditional banking has clear processes for transferring assets when someone dies. Self-custody? Not so much. If you're the only person who knows your seed phrase and something happens to you, those funds are gone forever.

Susanka acknowledges this is "really tough to do in a self-custodial, decentralized manner."

"You know, there are always ideas like 'let's put part of your recovery seed in your parents' Google Drive,' but we don't want to be dependent on Google. We don't want to be dependent on Apple. And when you really lay out all these conditions, it's really tough to bring something up."

For now, solutions like ETFs offer a pragmatic compromise — they sacrifice some sovereignty and privacy, but provide clear inheritance mechanisms through traditional financial systems.

šŸ“Š The Market Reality

When asked about the current bear market sentiment and whether people should still care about Bitcoin, Susanka's response cuts to the core:

"The story, the narrative behind Bitcoin hasn't changed. Now the price dropped and everyone is interested in AI — no one really cares about Bitcoin anymore. But the reason why Bitcoin emerged and the reason why Bitcoin exists, that's something that still is something we need."

Fiat currencies remain unbacked. The gold standard is gone. People still need ways to preserve wealth outside traditional financial systems. These fundamentals haven't changed, regardless of whether Bitcoin is trading at all-time highs or 50% down.

"It's up and down," he says simply. "I really feel like next year it's going to be completely different."

āœ… The Bottom Line

The crypto industry has oversold the idea that self-custody is easy. It's not. But it's also not as hard as people think.

The real challenge isn't technical — it's behavioral. It's the tired evening when you click the first Google result. It's the exciting opportunity that seems too good to be true. It's the backup you mean to check "next week."

Security isn't about being paranoid. It's about being prepared.

As Susanka puts it: "It's fine if you decide not to wear a helmet on a scooter, I suppose. But you need to know what the risks are. The education part is vital for the risk part."

The same applies to crypto. You don't have to self-custody everything. But you should at least understand what you're giving up when you don't.

Because in a world where even the experts can almost fall for phishing scams, awareness might be the most valuable security tool we have.

More from When Shift Happens

šŸš€ Inside Kinetic: The $2.5B Protocol Amplifying Hyperliquid's Vision
Summary

The Architect Behind Hyperliquid's Largest Protocol on L2s, Liquid Staking, and

When Shift Happens•
2d ago

šŸ’¼ From Hotelier to Hyperliquid's HeavyweightThe trajectory from luxury hospitality to building one of crypto's fastest-...

WatchRead more
šŸ”„ Why Crypto's Best Returns Are Still Ahead — Jupiter's COO on Infinite Capitalism
Summary

The Everything Chain: Why Solana's Infrastructure Play Is Just Getting Started

When Shift Happens•
Aug 20

šŸ“Š The State of Crypto: Moving From Innovators to Early Majority Despite narratives claiming crypto's best opportunitie...

WatchRead more
⚔ From Engineering MIT to Bitcoin's Infinite Half-Life: The Absolute Scarcity Revelation
Summary

How Zero Interest Rates and Thermodynamic Engineering Unlocked the Discovery of

When Shift Happens•
Aug 19

🧭 Time Horizons, Dynamic Systems, and the Engineering of Renaissance PoliticsThe foundation for understanding monetary ...

WatchRead more
🐢 The Boring Path to Crypto Wealth: Why Long-Term Conviction Beats Short-Term Trading
Summary

Slow Money: The Case for Patient Capital in Crypto Markets

When Shift Happens•
Aug 18

šŸ’° The Uncomfortable Truth About Getting Rich in CryptoThe question everyone asks—how do I get rich with crypto?—has a s...

WatchRead more
šŸŽÆ Five Years, Two Bear Markets, One Mission: Building Derivatives Infrastructure That Actually Matters
Summary

The Long Game: How Derive Survived Multiple Near-Death Experiences to Become the

When Shift Happens•
Aug 11

šŸ’¼ Beyond the Hype: Building Real Financial InfrastructureIn an industry littered with failed projects and abandoned roa...

WatchRead more
šŸ  The Real Estate Illusion: Why Homeownership No Longer Works for Millennials
Summary

The Great Housing Disconnect: When America's Biggest Investment Becomes Its Wors

When Shift Happens•
Aug 10

šŸ’ø The Uncomfortable Truth About Real EstateThe promise was simple: buy real estate, watch it appreciate, build wealth. ...

WatchRead more