top of page

Why Smart People Still Get Scammed: Trezor CTO Tomáš Sušánka on AI, Self-Custody, and the Future of Bitcoin Security

Writer: Kevin Follonier
Kevin Follonier
Sep 2
5 min read

In this episode of When Shift Happens, I sit down with Tomáš Sušánka, CTO of Trezor, to discuss a problem that is becoming harder to ignore: how sophisticated technology is empowering scammers. We explore why intelligent people still fall for scams, how AI is transforming phishing and social engineering, what self-custody actually protects you from, and whether quantum computing could eventually threaten Bitcoin itself. 


From a Fascination With Bitcoin to Securing It


While studying computer science and cryptography at university in Prague, Tomáš remembers being fascinated by the idea that money could be created and coordinated through cryptography rather than a traditional financial institution. The technical question eventually led to a practical one: if wealth could exist digitally, how do you secure it? That question became central to his career and eventually his work as Trezor's CTO, overseeing the engineering and hardware behind their wallets.

His conviction in Bitcoin has also survived its market cycles. For Tomáš, price and attention can move elsewhere, but the reason Bitcoin interested him has not fundamentally changed. That longer-term perspective also shapes how he thinks about security. Protection should not begin after something goes wrong, but should be built around risks that may feel remote today.


Why Smart People Still Fall for Scams


Tomáš was shopping online one evening when he clicked the first Google result for a retailer. He browsed, selected items, and eventually showed the site to his wife. She immediately pointed out that it was a phishing website. The most unsettling thing wasn’t how convincing the website was but the fact that he fell for it.

“This can happen even to me,” he recalls. Tomáš has worked in security for years, yet being tired and outside his normal professional environment was enough for his usual instincts to switch off.


That story gets at one of the episode's most important ideas. Scams do not necessarily succeed because the victim lacks intelligence, but because humans are inconsistent. People get tired, hasty, or excited by the possibility of recovering lost money. They may trust a familiar logo, or answer a message while distracted. An attacker does not need you to make bad decisions every day. They may only need you to make one bad decision at 11 p.m. after a long day.


Tomáš describes this as an asymmetric risk problem: the probability of something going wrong may appear small, but the impact can be enormous. Humans are naturally poor at responding to those kinds of risks, especially when the threat is invisible or unfamiliar.


AI Is Making Trust Much Easier to Fake


That human vulnerability becomes more serious when AI enters the picture.

The old stereotype of the online scam was an obviously suspicious email filled with grammatical errors. That model is becoming obsolete. Today's attackers can combine email, WhatsApp, phone calls, and convincing identities over a period of days or weeks. AI makes fluent communication easier, enables voice cloning, and makes visual impersonation increasingly convincing.


Tomáš describes fake Microsoft Teams calls in which attackers used an AI deepfake of a recognizable person. The call itself was not necessarily the attack. The objective was to convince the victim that there was a technical problem and get them to download something malicious. The danger is increasingly not simply who appears on your screen, but what the interaction eventually persuades you to do.


Tomáš's advice is consequently practical. Be suspicious of unexpected urgency, avoid installing files or software because someone on a call tells you to, stay in the browser where possible, and verify unusual requests through another channel. He has even stopped answering calls from unknown numbers because a short conversation can provide material for voice cloning.

AI, however, is not purely an offensive technology. Tomáš points out that the same tools helping attackers can help developers identify bugs, improve software, and strengthen defensive systems. In his view, AI is making both sides more capable.


Good Security Has to Be Usable


Perhaps Tomáš's most useful principle is one that sounds contradictory at first: “Security at the cost of usability comes at the cost of security.”

A theoretically perfect security system is useless if ordinary people cannot realistically follow it. You could hide a Bitcoin backup somewhere deep in a forest and make it extraordinarily difficult for anyone to steal. But if accessing your own money becomes almost impossible, the system has failed in another way. Trezor therefore thinks about security alongside usability and privacy rather than treating security as an isolated objective.

This tension sits at the heart of self-custody.


A hardware wallet gives users something an exchange cannot: direct control. When assets sit with a custodian, the user ultimately depends on that company's infrastructure and rules. With self-custody, that dependence is reduced. But independence comes with responsibility.

Tomáš is pragmatic about this. He does not argue that everyone needs to immediately move everything into self-custody. Small amounts on an exchange can make sense, particularly for active trading. People can also transition gradually, learning how a hardware wallet works before moving larger amounts.


The larger challenge is making that experience intuitive enough for mainstream users. Seed phrases remain one obvious weakness. Asking someone to protect digital wealth by writing 12 or 24 words on paper can feel strangely archaic, and those same words become an attack surface when phishing sites persuade users to type them online. Inheritance is another unresolved problem. Banks have established processes when an account holder dies. Reproducing that experience without reintroducing a centralized intermediary is much harder.


Quantum Computing and the Risk You Cannot Ignore


Tomáš does not expect a cryptographically relevant quantum computer in the immediate future. But he also refuses to dismiss the possibility entirely. So once again, the conversation returns to asymmetric risk.

The probability may be extremely low, he argues, but it is not zero. If a sufficiently powerful quantum computer could eventually compromise cryptographic systems, then the potential impact is large enough to justify preparing before the threat arrives.


Bitcoin presents an additional challenge because decentralization, one of its greatest strengths, can also make coordinated upgrades slower. A company can simply set a deadline and order its engineering organization to migrate to a new security standard. Bitcoin has no CEO capable of doing that. Reaching consensus can take time, which is precisely why Tomáš believes these conversations need to happen early.


Security Is Less About Paranoia Than Preparation


The most useful lesson from Tomáš's journey may be that good security is not about living in constant fear. It is about understanding what can go wrong and building habits before the moment arrives.

His recommendations include understanding where your assets are, knowing how they are protected, verifying unusual requests, reducing unnecessary points of failure, and never leaving security maintenance for “later.” Those small tasks are easy to postpone precisely because nothing appears to be wrong, but security works best when you deal with them before something is.


👉If you enjoyed reading the summary, head over to When Shift Happens on YouTube or your favorite podcast platform to access the full convo. 


Comments


  • Twitter
  • Youtube
  • Instagram
  • LinkedIn
  • Spotify

©2025 Kevin Follonier

Content is for educational and entertainment purposes only and does not constitute financial advice

bottom of page