A phishing site masquerading as Trezor climbed to the top of Google’s sponsored search results on August 7, 2026, siphoning funds from users who were tricked into entering their wallet recovery phrases. The fake page, hosted on Google’s own Sites platform, mimicked Trezor’s legitimate interface closely enough that at least one victim reportedly lost their entire life savings.
How the scam worked
The phishing page was hosted at a URL beginning with sites.google.com/view/start-trezor-suite, which lent it an air of legitimacy that a random domain wouldn’t have carried. Google Sites is a free website builder anyone can use, and hosting a scam there meant the URL at least started with a domain most people instinctively trust.
Once on the page, users were prompted to enter their 12- or 24-word recovery phrases, the master keys to their crypto wallets. Hardware wallets like Trezor generate these seed phrases during initial setup, and anyone who possesses them can reconstruct and drain the wallet from any device, anywhere in the world.
Trezor confirmed it is aware of the incident and is working internally to escalate the matter. The company said it is collaborating with Google to get the fraudulent ad removed and has reminded users of a cardinal rule in crypto security: never share your seed phrase with anyone or any website, ever.







