Skip to content
Trezor User Claims Google Ad Redirected to Phishing Site, Life Savings Stolen

Trezor User Claims Google Ad Redirected to Phishing Site, Life Savings Stolen

Kucoin August 8, 2026

Headline: Trezor user says a Google ad led to phishing site — claims he lost his life savings A crypto user going by David (@ReallyBadDay99 on X) says he lost his life savings after clicking a Google result for “Trezor wallet” that allegedly redirected him to a phishing page impersonating the hardware-wallet maker. What happened - On Aug. 7 David posted that the top result for “Trezor wallet” led to a Google Sites page designed to look like Trezor’s site. He said the scam was collecting funds and pointed investigators to an on-chain address (bc1qrz33mr7tx8wrpcs2pxrvv83hqwpm907s9shkz4), which he claimed was “vacuuming up millions.” - At the time of publication, neither David’s loss, the total amount taken from other users, nor the address’s confirmed link to the phishing page had been independently verified. Why this is dangerous - Hardware-wallet recovery (seed) phrases — typically 12, 20 or 24 words — give full control of the associated cryptocurrency. Entering a recovery phrase on a fraudulent site lets attackers restore the wallet on another device and transfer assets without needing the physical hardware. - Blockchain transactions are generally irreversible, so victims have limited options once funds are moved. Trezor’s response - Hours after David’s post, Trezor warned users it had spotted an uptick in phishing sites impersonating the company, some appearing as results that look convincing. - The company reiterated: never enter your wallet backup on a website or it with anyone. Users should verify they’re on the official site before downloading Trezor Suite or entering wallet information. - Trezor did not confirm David’s reported loss, identify who was behind the phishing page, estimate the campaign’s takings, or say whether the specific Google Sites page had been removed. Wider pattern and context - ads have become a frequent vector for crypto phishing: attackers buy ads for wallet, exchange and DeFi queries so malicious pages appear above legitimate results. - Earlier this year, fake Uniswap ads reportedly helped scammers steal at least $400,000, and Security Alliance data linked malicious Google ads to roughly $1.27 million in losses between March 13 and March 30, while the group blocked hundreds of malicious ad links over the prior year. - Attackers also host phishing pages on reputable platforms like Google Sites to appear more trustworthy. Google acknowledged in a June fraud advisory that scammers were abusing trusted cloud services to host phishing content and evade filters. - Related scams include mailed fake Trezor and Ledger letters containing QR codes that led to phishing pages requesting seed phrases. What users should do now - Never enter your seed/recovery phrase into a website, email, or chat. No legitimate wallet provider will ask for it online. - Bookmark your wallet provider’s official site and download wallet software only from verified channels. - If you entered a recovery phrase on a suspicious page, assume the wallet is compromised: create a new wallet, generate a fresh backup, and move any remaining funds to the new address immediately. - Report the incident to your wallet provider, the hosting/advertising platform (e.g., Google), and local law enforcement. Consider notifying on-chain investigators or security firms for tracing, but understand that blockchain transfers are typically irreversible. This incident underscores how targeted phishing via ads and trusted hosting services continues to threaten crypto holders who rely on engines to access wallet services. At the time of reporting, no U.S. regulator or law-enforcement agency had publicly announced an investigation into David’s claim.

Extracted Entities