← Radar

Incident case file

Sign in to watch

Trezor Google Ads Phishing Campaign — Seed Phrase Harvesting

Incident date 2026-08-05Last updated Aug 14, 2026

3 views

ActiveBitcoinPhishing campaignCluster: TREZOR-PHISH-2026-08

Estimated loss

$1.6M

Victims identified

1
Victim group joining is coming soon.

Investigation

55%

Facts and investigation

Ledger

Attacker

MISSING — funds traced manually through 3 hops on-chain, but the final recipient entity remains unidentified. Collection address (confirmed via victim's own public post): bc1qrz33mr7tx8wrpcs2pxrvv83hqwpm907s9shkz4.

Funds moved to

24.04135820 BTC (~$1.6M) received at collection address bc1qrz33mr7tx8wrpcs2pxrvv83hqwpm907s9shkz4 across 80 transactions (mempool.space-verified). Traced through 3 hops: Hop 2 — bc1qqg3c0ed0wzjdnjjlgcdrzyzedj8tgyapkvda9z (received 9.7 BTC on Aug 7 at 08:30:02 UTC plus 0.846 BTC on Aug 7 at 10:42:22 UTC, totaling 10.546 BTC). Hop 3 (current holding address, mempool.space and Arkham Intelligence-verified) — bc1qhluxs8yfper7sxnmpgpjy9e38dx4qxpuhen5cs, currently holding 27.313 BTC (~$1.77M) acc

Linked

A fraudulent Trezor Suite website was hosted on Google Sites (sites.google.com/view/start-trezor-suite) and promoted via a paid Google-sponsored search advertisement that outranked Trezor's own official website for the search term 'Trezor wallet.' The victim (David, @ReallyBadDay99) publicly disclosed the harvesting address and tagged on-chain investigators @zachxbt and @CertiK for further investigation on August 6, 2026 at 19:56 UTC. Trezor's official account publicly acknowledged and escalated

Chronology

1 beat
  1. T-X: An attacker purchases a Google Ads sponsored search placement designed to outrank Trezor's official website for the query 'Trezor wallet,' directing unsuspecting users to a fraudulent website cloned and hosted on Google Sites (sites.google.com/view/start-trezor-suite) — deliberately leveraging the inherent trust users place in the google.com domain. T0 (on or before August 6, 2026): A victim, David, enters his 12/20/24-word wallet recovery seed phrase directly into the fraudulent page after being directed there via the sponsored search advertisement, immediately granting the attacker full control of his Bitcoin wallet. August 6, 2026, 19:56 UTC: David posts publicly on X: 'Hey @Trezor, just lost my life savings. Top sponsored Google result for 'Trezor wallet' is a phishing site!... Harvesting address is currently sitting at: bc1qrz33mr7tx8wrpcs2pxrvv83hqwpm907s9shkz4,' tagging prominent on-chain investigators @zachxbt and @CertiK for assistance. Later August 6, 2026: Trezor's official account publicly responds, apologizing, thanking David for the report, and stating the phishing page and address are being escalated internally and reported through relevant takedown channels. On-chain data (mempool.space, independently verified) confirms the harvesting address received a total of 24.04135820 BTC (approximately $1.6M at roughly $65,172/BTC at the time) across 80 separate transactions; nearly all funds are moved out of the address shortly after receipt, leaving only approximately 0.04 BTC behind. Manual on-chain fund tracing (conducted August 8, 2026) follows the stolen funds through two subsequent hops. First, 9.7 BTC and 0.846 BTC are sent respectively at 08:30:02 UTC and 10:42:22 UTC on August 7 to an intermediate address (bc1qqg3c0ed0wzjdnjjlgcdrzyzedj8tgyapkvda9z), which itself immediately forwards both received amounts onward to a third address (bc1qhluxs8yfper7sxnmpgpjy9e38dx4qxpuhen5cs). This third address is confirmed to be a convergence point that has received funds from at least five additional, apparently unrelated sources between August 4-7, accumulating a total balance of 27.313 BTC (approximately $1.77M) with zero outflows observed as of the investigation date. This pattern is consistent with either a cryptocurrency exchange deposit wallet, a mixing or coinjoin-style service, or simply a personal consolidation wallet belonging to the threat actor — however, Arkham Intelligence's free-tier lookup returns no entity label or exchange tag for the address, leaving its true nature unresolved by publicly available tools. August 7-8, 2026: Trezor publishes a broader public advisory warning of a general rise in phishing websites impersonating its brand via sponsored search placements, and CryptoTimes separately reports the underlying campaign may have affected as many as 80 total victims — a figure that could plausibly reflect either the 80 individual transactions received from the single confirmed victim, or a wider, multi-victim campaign scope; this ambiguity has not been definitively resolved as of the reporting window's close. No arrests, fund recovery, or attacker identification have been publicly confirmed.

Sources and coverage

Victim testimonies

No testimonies yet.

+ Add my testimony → (coming soon)