
A crypto user says he lost his life savings after a sponsored Google result impersonated Trezor. Trezor warned of rising phishing sites in search ads.
Alpha Score of 75 reflects strong overall profile with moderate momentum, moderate value, strong quality, strong sentiment.
A crypto user who posts on X as @ReallyBadDay99 and goes by David said he lost his life savings after clicking a sponsored Google result that impersonated Trezor.
"Hey @Trezor, just lost my life savings. Top sponsored Google result for 'Trezor wallet' is a phishing site!" David wrote on Aug. 7.
The sponsored ad directed him to a page hosted on Google Sites that copied the hardware-wallet provider's appearance. David said the phishing operation fed funds to an address he shared with on-chain investigators ZachXBT and CertiK. He also claimed the address was "vacuuming up millions."
Trezor issued a broader warning hours later, saying it was seeing an increase in phishing sites impersonating the company. Some of the fraudulent pages appear in sponsored search results and can look "highly convincing," the company wrote on X. Trezor warned that entering a wallet backup on those pages could result in stolen funds.
"Never enter your wallet backup on a website or share it with anyone," the company said.
A wallet recovery phrase gives its holder full control over the associated cryptocurrency. A victim who types the phrase into a fake site hands the attacker the keys to restore the wallet and drain its assets. Blockchain transactions are almost always irreversible.
Trezor did not confirm David's individual loss, name the phishing page's operators, or say whether the specific Google Sites link had been taken down. Nor did it estimate the total stolen in the campaign.
Sponsored search results have become a repeated delivery method for crypto phishing. Attackers buy ads for wallet, exchange, and DeFi search terms so fraudulent pages rank above legitimate ones. In May, fake Uniswap ads promoted through Google search helped scammers steal at least $400,000 from several users, crypto.news previously reported.
Security Alliance data connected malicious Google ads to roughly $1.27 million in losses between March 13 and March 30. The group said it had blocked more than 356 malicious advertising links over the prior year.
Hosting the fake Trezor page on Google Sites fits a pattern where attackers abuse trusted cloud platforms to bypass security filters. Google itself acknowledged in a June fraud advisory that scammers were "levering" (the source text says leveraging) its own infrastructure to host phishing content.
Crypto.news also reported in February that scammers mailed fake Trezor and Ledger letters with QR codes linking to phishing sites. Those pages asked for 12-, 20-, or 24-word recovery phrases under the pretext of verifying wallet ownership. The delivery method differed, but the goal was the same: trick users into handing over their seed phrases.
No U.S. regulator or law-enforcement agency had publicly announced an investigation into David's reported loss at the time of publication. Trezor directs customers to bookmark its official website and download Trezor Suite only through verified company channels. Anyone who entered a recovery phrase on a suspicious page should treat the wallet as compromised and move remaining funds to a new wallet with a fresh backup.
Drafted by a large language model from the source reporting linked above, then screened by automated publishing checks. It is not read by a journalist before publication. Some articles cite our Alpha Score. Verify prices and figures against the original source. Educational coverage, not personalized advice.