Buy now

The most effective attack on a hardware wallet in 2026 doesn't involve the hardware. A vishing attack works over the phone, uses your own caution against you, and ends with you typing your recovery words into a window that looks exactly like the software you've opened a hundred times before. No exploit, no cracked chip, no cryptography broken anywhere along the way.

What a vishing attack is

Vishing is phishing conducted by voice. Rather than sending an email and hoping you click, the attacker calls you, or arranges things so that you call them, and works through a script designed to move you toward an action you'd refuse if you'd thought about it for ten uninterrupted minutes.

The phone changes the psychology in ways that matter. Email gives you time to reread a sentence and notice the domain is wrong, while a live conversation runs at the speed of speech, adds social pressure, and lets the caller adapt to whatever objection you raise. A person who sounds calm and knows your order number does not feel like a stranger.

Scale is the reason this keeps growing. The FBI's 2025 Internet Crime Report logged more than 80,000 complaints across tech, customer support, and government impersonation, with losses above 2.9 billion dollars, while cryptocurrency-related complaints reached 181,565 and accounted for over 11 billion dollars on their own.

Why crypto holders get called

Calling random numbers wastes time, so the work happens before the phone rings. Attackers want a list of people who hold crypto, and breaches supply it: a leak at a shipping provider exposed the names, addresses, phone numbers, and order details of 13,689 Trezor customers between May and August 2026, and Trezor's own support portal leaked contact details for up to 66,000 people back in January 2024.

Lists like those are valuable because they remove all the guesswork. The caller already knows you own a hardware wallet, knows which brand, and can reference a delivery you remember receiving.

Rapid7 Labs found the industrial version of this while examining a misconfigured directory belonging to a fraud operation it named Operation ASTERIX, documented on 17 August 2026 by researchers Anna Širokova and Jan Recinsky. The directory held roughly 885,000 phone numbers alongside tooling that tested each one against crypto exchange accounts before a call was placed. On the largest set, 316,002 German mobile numbers, the checks confirmed 43,066 exchange accounts, a hit rate near 13.6%.

Anatomy of a vishing attack

The sequence Rapid7 recovered is worth walking through, because every step exists to answer a doubt you might have raised.

It opens with an email that creates a support case and gives you a verification code, which does two useful things for the attacker: it plants a reference number in your inbox, and it makes the later call feel like a response to something already underway. When the caller rings, they quote that code back to you, along with your name, your location, and details drawn from the breach data. Nothing about the conversation resembles a cold approach from a stranger who found your number in a directory.

The pretext is usually urgency wearing a helpful face. Your wallet software needs updating, suspicious activity has been flagged against your account, a security patch has to be applied today. You're then guided toward downloading what you believe is your own wallet application, and because you've been walked there by someone who already proved they know who you are, the download feels like following instructions rather than taking a risk.

The application that waits

What arrives is a counterfeit. Rapid7 recovered three builds, with fake Trezor Suite the most polished, sitting alongside imitations of Ledger Live and Exodus, packaged for both macOS and Windows.

The fake Trezor Suite build showed patience that ordinary malware doesn't bother with. It launched as a hidden, transparent window and scanned the running process list every five seconds, waiting for you to open the legitimate application. The moment you did, it killed that process and brought its own interface forward, so the window you were looking at was one you had opened yourself. It then asked for a recovery phrase of twelve, eighteen, twenty, or twenty-four words plus any passphrase, and forwarded everything typed to a Telegram bot along with your IP address. Two macOS LaunchAgents kept it alive across reboots.

The researchers also noted that the operators used GitHub Copilot to write and refine their code, including attempts to talk the assistant past its own safety guardrails. The craft floor for this kind of attack has dropped, which is worth factoring into how much polish you assume a scam will lack.

How to shut a vishing attack down

One habit defeats nearly all of this: never continue a conversation on a channel the other party chose.

Hang up, then reach the company yourself using a number or address you looked up independently. A caller who knows your order number has proved only that they read a leaked file, and no legitimate support process is damaged by you calling back on a published line. Should the caller push back on that, resist harder, because urgency is the tell rather than the emergency.

Beyond the call-back rule, a few things hold up well. Type software URLs by hand instead of following links or search results, since a phishing site impersonating Trezor has previously reached the top of Google through paid placement. Treat any request for your recovery phrase as an attack in progress, whoever appears to be asking. Assume caller ID is forged, because it costs nothing to spoof. Keep in mind that a company contacting you about a breach will not need you to prove anything about your wallet.

The structural problem underneath the call

Every version of this attack aims at one target. Your recovery words are the wallet, they can be read aloud or typed in a moment of confusion, and once they're gone there's nothing to revoke and nobody to call. A pipeline like ASTERIX exists because that single string is worth the effort of building fake applications and staging 885,000 phone numbers.

We designed TapSafe Recovery around removing that concentration. Access is split rather than stored in one recitable phrase: your Recovery Tag holds 50%, your paired phone holds 50% encrypted into your own iCloud or Google Drive instead of on the handset, and optional Recovery Contacts hold 25% each while learning nothing about your wallet. Because no single piece restores anything by itself, there's no complete answer a caller can talk you into giving.

On the Ryder One, keys are generated inside an EAL6+ certified Infineon SLC38 secure element and never leave it, the firmware was independently audited by Halborn with the full report published, and each transaction renders in readable detail on the 1.6-inch screen before you approve it. Communication runs over NFC and nothing else, so there's no wired data path and no Bluetooth radio in the picture. Your seed phrase remains available on the device as a last resort and follows the BIP-39 standard, which keeps you free to leave.

Hardware security has been ahead of the attackers for years, and the attackers responded by going around it and calling you instead. Build a setup where the phone call has nothing to win.

Hold your keys in a way that survives a convincing conversation. Get your Ryder One.


Meta description: A vishing attack skips the hardware and calls you instead. How Operation ASTERIX ran fake wallet apps and 885,000 phone numbers, and how to shut the call down.

Meet Ryder One

Meet Ryder One
Meet Ryder One

The only crypto wallet you can install on a crowded subway.
Set it up in less than 60 seconds and just tap your phone to send, swap, and recover.

Learn More