Trezor warned on Aug. 7 that it is seeing more phishing websites impersonating the hardware-wallet company, including some that appear in sponsored Google search results. The alert came after an X user identified as David, posting as @ReallyBadDay99, said he lost his “life savings” after clicking what he described as the top sponsored result for “Trezor wallet.”

Trezor did not confirm David’s reported loss or identify those behind the alleged phishing page. But the company said users should not assume a sponsored search result is legitimate and should verify they are on Trezor’s official website before downloading software or entering any wallet-related information.

User says a sponsored result led to a fake Trezor page

According to David’s Aug. 7 post on X, the sponsored Google result directed him to a phishing page hosted on Google Sites that impersonated Trezor. He said the operation was collecting funds through an address he shared with blockchain investigator ZachXBT and security firm CertiK.

David also alleged that the address was “vacuuming up millions.” At the time of publication, however, neither the size of his loss, nor the broader amount allegedly taken from other users, nor the claimed link between the wallet address and the phishing site had been independently verified.

Why recovery phrase theft can empty a wallet

A wallet recovery phrase gives whoever holds it control over the associated crypto assets. If that phrase is entered on a fraudulent website, an attacker can recreate the wallet on another device and move the funds without needing the original hardware wallet itself.

Because blockchain transfers are generally irreversible, victims often have little recourse once assets have been moved. That makes phishing pages designed to collect backup phrases especially dangerous for hardware-wallet users.

Trezor issues a broader warning

Hours after David’s post, Trezor said it was observing an increase in phishing sites posing as the company. It warned that some of those pages were appearing in sponsored search results and could look convincing enough to mislead users.

In its Aug. 7 message on X, Trezor told customers never to enter a wallet backup on a website or share it with anyone. The company also said users should confirm they are on the official Trezor site before downloading Trezor Suite or providing any wallet-related information.

Trezor’s statement did not confirm David’s account, estimate the scale of the campaign, or say whether the specific Google Sites page cited in his post had been removed.

Sponsored ads remain a recurring phishing channel

Paid search results have repeatedly been used to deliver crypto scams. Attackers buy advertisements tied to wallet, exchange and decentralized finance keywords so fraudulent pages can appear above legitimate services in search results.

Crypto.news previously reported that fake Uniswap ads shown through Google search were linked to at least $400,000 in thefts in May. In that same report, Security Alliance data tied malicious Google advertisements to about $1.27 million in losses between March 13 and March 30, and said the group had blocked more than 356 malicious ad links over the prior year.

The use of Google Sites in the reported Trezor case fits another known tactic: hosting phishing content on trusted platforms to make it seem safer and to evade filters. Google said in a June fraud advisory that scammers were abusing reputable cloud services for that purpose.

What users are being told to do next

Trezor has previously faced similar impersonation attempts. In February, crypto.news reported that scammers mailed fake Trezor and Ledger letters with QR codes leading to phishing websites that asked for 12-, 20- or 24-word recovery phrases under the guise of wallet verification.

The company advises customers to bookmark its official website and obtain Trezor Suite only through verified channels. Anyone who has entered a recovery phrase on a suspicious page should treat the wallet as compromised and move any remaining assets to a newly created wallet with a fresh backup. No U.S. regulator or law-enforcement agency had publicly announced an investigation into David’s reported loss at the time of publication.

Source: crypto.news