Key Highlights
- Trezor warned of a rise in phishing websites impersonating its brand, with some fraudulent pages appearing in Google’s sponsored search results.
- A user reported losing personal savings after clicking a sponsored result for “Trezor wallet” that redirected to a phishing site requesting recovery information.
- Trezor urged users to verify the official website and never enter or share wallet backups online, as compromised recovery information can allow attackers to access and transfer funds.
Trezor, a crypto hardware wallet brand, has issued a public warning about an increase in phishing websites that impersonate its brand.
In an X post on Friday, Trezor noted that some of these fake sites have appeared in sponsored search results on Google. Trezor stated that the sites can look extremely convincing and that entering a wallet backup on one of them could result in the theft of funds.
User flags phishing activity
A Trezor user reported on the social media platform X that the top sponsored Google result for the search term “Trezor wallet” directed traffic to a phishing site. The user stated that the encounter led to the loss of personal savings.
The scam page was identified as a Google Sites address that collected recovery information. A related Bitcoin address associated with the activity was publicly shared by the user and flagged to blockchain investigators.
Trezor responded directly to the user report. The company expressed regret over the reported loss, confirmed that it was escalating the matter internally, and said it was reporting the phishing page through relevant channels. Trezor directed the affected user to its support team and repeated advice applicable to all users: always verify that the official Trezor website is being used, and never enter a wallet backup into any website or form.
In its broader advisory, Trezor emphasized that sponsored search results should not be assumed to be legitimate. The company reiterated that users should never enter a wallet backup on a website or share it with anyone.
The phishing activity involves collection of recovery data that can grant control over hardware-wallet-linked funds. Once recovery information is submitted to a fraudulent site, the associated assets can be transferred by the operators of the site.
Earlier security disclosure
The current phishing reports follow an earlier security disclosure by Trezor. On June 3, the company announced a vulnerability in the TROPIC01 secure element chip used in its Trezor Safe 7 hardware wallet.
The issue was identified during an independent audit conducted by Ledger’s Donjon team and was formally disclosed by Tropic Square. Trezor stated at the time that user funds, PINs, and backups remained secure and that no action was required from device owners. The disclosure process involved coordinated research between the audit team and Tropic Square’s engineering staff.
The incident illustrates the continued use of paid search placements to distribute convincing replicas of established cryptocurrency service sites. Users who follow sponsored links without additional verification steps remain exposed to loss of recovery data and subsequent asset transfers.
Also Read: 15 Attackers Exploit Ongoing Coldcard Hack as Losses Approach $130M
