Share
THREAT REPORT - HARDWARE WALLET PHISHING

The fake Trezor page was hosted on google.com. So was the ad that sent people to it.

A Trezor user searched for their own wallet software, clicked the first result, and reached a page asking for their recovery phrase. Every piece of advice about checking the domain would have told them the page was fine.

SafeBrowz Threat Research Security ResearchAugust 10, 20267 min read

Verdict: a Trezor page you reached from an ad is not Trezor.

On 6 August 2026 a Trezor user posted that the top sponsored Google result for "Trezor wallet" led to a fake Trezor page hosted on Google Sites, which asked for their wallet recovery information (report). The amounts circulating have not been independently verified, so treat the figures with care. What is not in doubt is the mechanic: the ad was bought, the page sat on a domain nobody would question, and the ask was a recovery phrase. Trezor never asks for it. Reach Trezor Suite only from a bookmark or by typing trezor.io yourself.

SafeBrowz judges the page you land on, even when it lives on a domain you trust. Add to Chrome, free Get the free Android app or scan a URL now →

What the victim actually did wrong: nothing unusual

The sequence is worth walking through slowly, because there is no careless step in it. A person who already owns a Trezor searches for "Trezor wallet". Google returns a sponsored result at the top. They click it, land on a page carrying Trezor's name and look, and are asked to complete a wallet setup. The page requests their recovery information. That is the whole attack.

No suspicious email arrived. No stranger messaged them. They were not offered free crypto. They went looking for a product they already owned, using the search engine everyone uses, and the first thing it showed them was the trap.

Trezor's own guidance is the line that matters here: never enter your wallet backup on a website or share it with anyone. The company said it was escalating the report internally and reporting the page through the relevant channels.

Why "check the domain" gave the wrong answer

The page was hosted on Google Sites, so its address genuinely began sites.google.com. Hover it, read it aloud, paste it to a friend, run it past a corporate filter: every one of those checks returns "google.com", and google.com is about as trusted as a domain gets.

This is the part people find hardest to accept. Google Sites is a free publishing product. Anyone can create a page on it in a couple of minutes, and that page inherits an address on one of the most trusted domains on the internet. The platform is legitimate. Most pages on it are somebody's school project or club noticeboard. The trust that belongs to Google's own services quietly extends to whatever a stranger published this morning.

So the advice that has protected people for a decade, look at the domain, produces a confident green light on exactly the page that empties the wallet. We wrote about a related version of this borrowed-trust problem in the phishing chain that starts on google.com, and about the same trick on developer platforms in free-hosting wallet drainers.

The one question that still works

If the domain cannot tell you, the page's request can. A hardware wallet exists so that your recovery phrase never touches an internet-connected device. That is the entire product. So the moment any page, any app, any support agent asks you to type those words, the answer is settled regardless of what the address bar says.

The same holds for the softer variants. A page asking you to "validate", "sync", "migrate" or "re-verify" your wallet is asking for the same thing in nicer clothes. Trezor, Ledger and every other hardware wallet handle recovery on the device itself, never in a browser field. We broke down the email version of this in fake Trezor emails and the seed phrase trap and the fake Ledger warning.

How much the ad channel is costing people

This is not a one-off. The Security Alliance found that phishing tied to malicious Google advertisements took more than $1.27 million between 13 and 30 March 2026 alone, said it had blocked over 356 malicious ad links across the year, and listed the hardware wallet brand Ledger among the targets (writeup). Fake Uniswap advertisements on Google reportedly helped scammers steal at least $400,000 in May. Buying the top slot above a wallet's own listing is now a repeatable business, not a stunt.

It works because the ad auction sells attention, not identity. The reputation checks that would catch a lookalike domain never fire, because there is no lookalike domain to catch. We covered the mechanics of that market in the first Google ad for MetaMask is sometimes a drainer.

Flag the page before you type anything into it

This is where a browser-side check earns its place, and it is worth being exact about how it handles this specific shape.

SafeBrowz runs three layers. The first is local, inside the extension: URL-shape checks, 60+ suspicious URL and urgency patterns, and homoglyph and Punycode detection, before a page renders. The second is server-side reputation and lists, where a database of 550+ impersonated brands and threat feeds decide whether a destination is known-bad or a lookalike of something real. Trezor sits in that brand set, with trezor.io recorded as its official home. The third is an AI read of the page content in over 100 languages, which is what catches a convincing new fake nobody has reported yet.

The detail that matters for this campaign is how we treat a page on a free-publishing platform. A non-root page on a host like Google Sites is treated as its own site and does not inherit the parent domain's trusted status, which is why the reported page sites.google[.]com/view/start-trezor-suite returns danger rather than borrowing google.com's reputation. Click it to run it through the scanner yourself. We also added page-level blocking for exactly this shape, so a single reported page can be blocked without ever touching the platform that hosts the millions of legitimate ones.

Honest scope, because it matters more than the pitch. Nothing here recovers funds after a recovery phrase has been entered, and a brand-new page that no layer has seen and that reveals nothing until after a click is the hard case for any scanner, ours included. That is why the behavioural check that opens a suspicious link in an isolated, disposable browser is part of the third layer for Premium users, and why the rule about never typing your recovery phrase is still the thing that actually protects you. SafeBrowz is free for the core protection, with Premium at $14.99 a year, on Chrome, Firefox and Edge plus the Android app, with Safari on the way.

If you already entered your recovery phrase

Speed matters more than certainty here. Assume the wallet is compromised and act as if funds are already moving.

  1. Move what is left, now. Create a brand new wallet with a fresh recovery phrase on a clean device and transfer everything out. The old phrase can never be trusted again, even if nothing has moved yet.
  2. Do not "restore" into anything. Typing the same phrase into another app or site, including anything offering to help you recover, hands it over a second time.
  3. Report the ad and the page. Google takes ad reports through the ad's own "why this ad" control, and the page can be reported to the hosting platform.
  4. Record the addresses. Note the receiving address from the transaction and report it to Chainabuse and to any exchange the funds touch. It rarely reverses a loss, but it is what builds a case and gets addresses flagged.

If you want the wider version of this, our what to do after a scam guide walks through the first 24 hours across payment types.

Paste a wallet link you are unsure about and see the verdict before you open it. Check a URL free → Get the free Android app
🛡 LIVE CHECK

Not sure whether a wallet page is the real one?

Paste the link before you open it, and never type a recovery phrase into anything. Our 3-layer engine (Local + APIs + AI) returns a verdict in about 3 seconds. Free, no signup.

Full scan with deep AI analysis → · No URL is logged to your identity.

Frequently asked questions

Was Google or Trezor hacked?

Neither. Google Sites is a free publishing product working exactly as designed, and the ad was bought through the normal auction. Trezor's software was not touched. What happened is that someone rented the top of the search results and published a page on a trusted host, which let a fake inherit two pieces of borrowed credibility at once.

How do I reach the real Trezor Suite safely?

Type trezor.io yourself or use a bookmark you made earlier, and download Suite only from there. Do not reach it through a search result, sponsored or organic, and do not reach it through a link in an email, a DM or a QR code on a letter. The bookmark is the whole defence, and it costs you one minute to set up.

My Trezor is a hardware wallet. Does that not protect me?

It protects the key, not the phrase. The device is built so your recovery phrase never has to leave it, which is why nothing legitimate ever asks you to type it into a browser. Once you type it into a web page, the attacker can rebuild your wallet on their own machine, and the hardware has nothing left to defend.

Can a scam page really sit on a google.com address?

Yes, on the free publishing parts of it. A page at sites.google.com/view/something is user-published content, not a Google service, in the same way a post on a social network is not written by the network. The address is genuine and the content is a stranger's, so the address tells you who hosts the page and nothing at all about who wrote it.

Would SafeBrowz have flagged this page?

The reported page returns danger in our scanner, and you can click the red link above to check it live. The reason it does is that we treat a non-root page on a free-publishing host as its own site rather than letting it inherit the parent domain's trusted status, and we have page-level blocking so one reported page can be blocked without affecting the platform. We are honest about the limit though: a freshly published page that no layer has seen yet is the hard case for any scanner, so the rule about never typing your recovery phrase is still what protects you.

Related SafeBrowz coverage

Follow on Google