Crypto news

09.08.2026
01:45

Phishing attack via Google Ads: Trezor user loses crypto savings

Trezor

Fraudulent schemes in the crypto industry continue to evolve, and this time a user of the popular hardware wallet Trezor has fallen victim. The incident, which came to light through social media, demonstrates how dangerous trust in search engine advertisements can be.

The victim, known by the nickname David, reported losing a significant portion of his savings after clicking on an advertising link in Google, having entered the query "Trezor wallet" in the search. The first position in the results turned out to be a fake page hosted on the Google Sites platform. Visually, it mimicked the official Trezor website, but when attempting to "connect" the wallet, the user was asked to enter their seed phrase—which is a gross violation of security rules on the part of the asset owner.

The address that, according to David, was used to collect the stolen funds has drawn the attention of analysts: approximately 24 BTC were received there, which at the time of writing exceeds $1.6 million, distributed across 80 transactions. However, it is important to emphasize: there is as yet no independent confirmation of a direct link between this wallet and the phishing site, nor of the exact size of the victim's personal losses. These data require additional verification, and I advise treating them with caution.

In response to the incident, Trezor representatives stated that they are already taking measures to remove the fraudulent page from search results. The company also reminded users of a critically important rule: the wallet backup—the seed phrase—must not be entered on any website, form, or application. This applies even to official resources, unless you are restoring the wallet in offline mode. Moreover, advertisements in search engines are not a guarantee of legitimacy, and trusting them blindly means exposing yourself to unjustified risk.

My view on the situation: This case is yet another reminder that even major platforms, such as Google, cannot fully protect users from social engineering. Fraudsters actively use the tools of legitimate services (for example, Google Sites) to create plausible traps. For investors, this is a signal: always check the URL manually, use bookmarks to access critically important services, and never enter your seed phrase in a digital environment unless it is an absolutely necessary step in the recovery process. Your assets are your responsibility, and vigilance here is the only reliable shield.