Trezor user says life savings stolen via Google phishing ad

Bybit
fiverr



A crypto user claims he lost his life savings after a sponsored Google result impersonating Trezor directed him to a phishing website.

Summary

  • David said a sponsored Google result led him to a fake Trezor website.
  • The phishing page was hosted on Google Sites and allegedly requested wallet recovery information.
  • Trezor reported an increase in phishing websites appearing in sponsored search results.
  • Similar Google ad campaigns were previously linked to more than $1 million in crypto losses.

Trezor user reports losing his life savings

A crypto user identified as David, who posts on X under the account @ReallyBadDay99, claimed on Aug. 7 that he lost his life savings after searching Google for “Trezor wallet.”

bybit

“Hey @Trezor, just lost my life savings. Top sponsored Google result for ‘Trezor wallet’ is a phishing site!” David wrote.

The sponsored result allegedly directed him to a page hosted on Google Sites that impersonated the hardware-wallet provider. David said the phishing operation was collecting funds through an address he shared with on-chain investigators ZachXBT and CertiK.

He also claimed the address was “vacuuming up millions.” However, the value of David’s loss, the total amount allegedly stolen from other users, and the address’s connection to the phishing website had not been independently verified at the time of publication.

A wallet recovery phrase gives its holder control over the associated cryptocurrency. If a victim enters the phrase on a fraudulent website, an attacker can restore the wallet on another device and transfer its assets without access to the original hardware wallet.

Blockchain transactions are generally irreversible, leaving victims with few options after funds have been transferred.

Trezor warns of sponsored phishing results

Trezor issued a broader warning hours after David published his claim, saying it was seeing an increase in phishing websites impersonating the company.

The hardware-wallet provider said some of the fraudulent websites were appearing in sponsored search results and could look highly convincing. It warned that entering a wallet backup on one of those pages could result in stolen funds.

“Never enter your wallet backup on a website or share it with anyone,” Trezor said in its Aug. 7 X post.

Trezor also told customers not to assume that a sponsored search result is legitimate. Users should verify that they are visiting the company’s official website before downloading Trezor Suite or entering information connected to their wallets.

The company’s post did not confirm David’s loss, identify the operators of the reported phishing page or estimate how much the campaign may have stolen. Trezor also did not say whether the specific Google Sites page identified in David’s post had been removed.

Google ads remain a recurring crypto attack vector

Sponsored search results have become a repeated delivery method for crypto phishing campaigns. Attackers purchase advertisements tied to wallet, exchange, and decentralized finance search terms, allowing fraudulent pages to appear above legitimate websites.

As previously reported by crypto.news, fake Uniswap advertisements promoted through Google search reportedly helped scammers steal at least $400,000 from several users in May.

Security Alliance data cited in that report connected malicious Google advertisements to approximately $1.27 million in losses between March 13 and March 30. The organization said it had blocked more than 356 malicious advertising links over the previous year.

The reported Trezor page being hosted on Google Sites also reflects a tactic in which attackers use trusted online services to make fraudulent pages appear safer. Google acknowledged in a June fraud advisory that scammers were abusing reputable cloud platforms to host phishing content and bypass security filters.

The continued use of Google’s advertising and hosting infrastructure makes the threat relevant to U.S. cryptocurrency holders who depend on search results to access wallet services. No U.S. regulator or law-enforcement agency had publicly announced an investigation into David’s reported loss at the time of publication.

Trezor users have faced similar phishing attempts

Crypto.news reported in February that scammers mailed fake Trezor and Ledger letters containing QR codes linked to phishing websites.

Those pages requested 12-, 20- or 24-word recovery phrases under the pretext of verifying wallet ownership. Although the delivery method differed, the campaign also relied on impersonating a trusted hardware-wallet provider and persuading users to disclose their backups.

Trezor advises customers to bookmark its official website and obtain Trezor Suite only through verified company channels. Anyone who entered a recovery phrase on a suspicious page should treat the wallet as compromised and move any remaining assets to a new wallet created with a fresh backup.



Source link

Bitbuy

Be the first to comment

Leave a Reply

Your email address will not be published.


*