Headline: Trezor user says a sponsored Google ad led to phishing site — claims he lost his life savings A crypto user going by David (@ReallyBadDay99 on X) says he lost his life savings after clicking a sponsored Google search result for “Trezor wallet” that allegedly redirected him to a phishing page impersonating the hardware-wallet maker. What happened - On Aug. 7 David posted that the top sponsored result for “Trezor wallet” led to a Google Sites page designed to look like Trezor’s site. He said the scam was collecting funds and pointed investigators to an on-chain address (bc1qrz33mr7tx8wrpcs2pxrvv83hqwpm907s9shkz4), which he claimed was “vacuuming up millions.” - At the time of publication, neither David’s loss, the total amount taken from other users, nor the address’s confirmed link to the phishing page had been independently verified. Why this is dangerous - Hardware-wallet recovery (seed) phrases — typically 12, 20 or 24 words — give full control of the associated cryptocurrency. Entering a recovery phrase on a fraudulent site lets attackers restore the wallet on another device and transfer assets without needing the physical hardware. - Blockchain transactions are generally irreversible, so victims have limited options once funds are moved. Trezor’s response - Hours after David’s post, Trezor warned users it had spotted an uptick in phishing sites impersonating the company, some appearing as sponsored search results that look convincing. - The company reiterated: never enter your wallet backup on a website or share it with anyone. Users should verify they’re on the official site before downloading Trezor Suite or entering wallet information. - Trezor did not confirm David’s reported loss, identify who was behind the phishing page, estimate the campaign’s takings, or say whether the specific Google Sites page had been removed. Wider pattern and context - Sponsored search ads have become a frequent vector for crypto phishing: attackers buy ads for wallet, exchange and DeFi queries so malicious pages appear above legitimate results. - Earlier this year, fake Uniswap ads reportedly helped scammers steal at least $400,000, and Security Alliance data linked malicious Google ads to roughly $1.27 million in losses between March 13 and March 30, while the group blocked hundreds of malicious ad links over the prior year. - Attackers also host phishing pages on reputable platforms like Google Sites to appear more trustworthy. Google acknowledged in a June fraud advisory that scammers were abusing trusted cloud services to host phishing content and evade filters. - Related scams include mailed fake Trezor and Ledger letters containing QR codes that led to phishing pages requesting seed phrases. What users should do now - Never enter your seed/recovery phrase into a website, email, or chat. No legitimate wallet provider will ask for it online. - Bookmark your wallet provider’s official site and download wallet software only from verified channels. - If you entered a recovery phrase on a suspicious page, assume the wallet is compromised: create a new wallet, generate a fresh backup, and move any remaining funds to the new address immediately. - Report the incident to your wallet provider, the hosting/advertising platform (e.g., Google), and local law enforcement. Consider notifying on-chain investigators or security firms for tracing, but understand that blockchain transfers are typically irreversible. This incident underscores how targeted phishing via sponsored search ads and trusted hosting services continues to threaten crypto holders who rely on search engines to access wallet services. At the time of reporting, no U.S. regulator or law-enforcement agency had publicly announced an investigation into David’s claim.
Trezor User Claims Google Ad Redirected to Phishing Site, Life Savings Stolen
ChainGPTShare
A crypto user known as David (@ReallyBadDay99 on X) reported losing his life savings after clicking a Google ad for 'Trezor wallet' that led to a phishing site. The page, hosted on Google Sites, mirrored Trezor’s official site and collected funds via an on-chain address. Trezor urged users to confirm they are on the official site before entering wallet details. The incident is part of a broader trend in crypto news, with phishing sites increasingly using trusted platforms. No U.S. regulator has announced an investigation into the claim.
Source:Show original
Disclaimer: The information on this page may have been obtained from third parties and does not necessarily reflect the views or opinions of KuCoin. This content is provided for general informational purposes only, without any representation or warranty of any kind, nor shall it be construed as financial or investment advice. KuCoin shall not be liable for any errors or omissions, or for any outcomes resulting from the use of this information.
Investments in digital assets can be risky. Please carefully evaluate the risks of a product and your risk tolerance based on your own financial circumstances. For more information, please refer to our Terms of Use and Risk Disclosure.



