Kucoin Phishing Scam via Google Ads Steals Millions from Trezor Users
Article Content
- •A phishing site impersonating Trezor stole approximately $1.6 million from users.
- •The fraudulent page was hosted on Google Sites, enhancing its perceived legitimacy.
- •Trezor has issued warnings and is collaborating with Google to address the issue.
A phishing scam impersonating Trezor appeared at the top of Google search results, leading users to a fraudulent site that collected wallet recovery phrases. A victim identified as David reported losing his life savings, approximately 24.04 BTC valued at $1.6 million, after entering his recovery seed on the phishing page. The page was hosted on Google Sites, making it appear legitimate. Trezor confirmed the incident and warned users against entering recovery phrases on any website. The attack highlights a growing trend of phishing schemes using Google ads to mislead crypto users. Trezor has escalated the issue internally and is working with Google to remove the fraudulent site. The incident underscores the importance of verifying URLs and avoiding entering sensitive information online.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (6)
Following this threat?
Track Trezor in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical WSO2 API Manager Vulnerability Under Active Exploitation A critical vulnerability (CVE-2026-5430) in WSO2 API Manager is being actively exploited, allowing unauthenticated attackers to forge admin tokens via JWT authentication bypass. This flaw, which has a CVSS score of 10.0, affects multiple WSO2 products including API Manager, Universal Gateway, Traffic Manager, and API…
Critical Linux Kernel Vulnerability CVE-2025-39682 Under Active Exploitation A critical vulnerability (CVE-2025-39682) in the Linux kernel allows remote code execution through mishandling of zero-length TLS records. This flaw affects kTLS-enabled hosts running vulnerable kernel versions, exposing them to attackers without authentication. CISA added this vulnerability to its Known Exploited…