Incident case file
Sign in to watchTrezor Google Ads Phishing Campaign — Seed Phrase Harvesting
3 views
Estimated loss
Victims identified
Investigation
Facts and investigation
Ledger
Attacker
Funds moved to
Linked
Chronology
1 beatT-X: An attacker purchases a Google Ads sponsored search placement designed to outrank Trezor's official website for the query 'Trezor wallet,' directing unsuspecting users to a fraudulent website cloned and hosted on Google Sites (sites.google.com/view/start-trezor-suite) — deliberately leveraging the inherent trust users place in the google.com domain. T0 (on or before August 6, 2026): A victim, David, enters his 12/20/24-word wallet recovery seed phrase directly into the fraudulent page after being directed there via the sponsored search advertisement, immediately granting the attacker full control of his Bitcoin wallet. August 6, 2026, 19:56 UTC: David posts publicly on X: 'Hey @Trezor, just lost my life savings. Top sponsored Google result for 'Trezor wallet' is a phishing site!... Harvesting address is currently sitting at: bc1qrz33mr7tx8wrpcs2pxrvv83hqwpm907s9shkz4,' tagging prominent on-chain investigators @zachxbt and @CertiK for assistance. Later August 6, 2026: Trezor's official account publicly responds, apologizing, thanking David for the report, and stating the phishing page and address are being escalated internally and reported through relevant takedown channels. On-chain data (mempool.space, independently verified) confirms the harvesting address received a total of 24.04135820 BTC (approximately $1.6M at roughly $65,172/BTC at the time) across 80 separate transactions; nearly all funds are moved out of the address shortly after receipt, leaving only approximately 0.04 BTC behind. Manual on-chain fund tracing (conducted August 8, 2026) follows the stolen funds through two subsequent hops. First, 9.7 BTC and 0.846 BTC are sent respectively at 08:30:02 UTC and 10:42:22 UTC on August 7 to an intermediate address (bc1qqg3c0ed0wzjdnjjlgcdrzyzedj8tgyapkvda9z), which itself immediately forwards both received amounts onward to a third address (bc1qhluxs8yfper7sxnmpgpjy9e38dx4qxpuhen5cs). This third address is confirmed to be a convergence point that has received funds from at least five additional, apparently unrelated sources between August 4-7, accumulating a total balance of 27.313 BTC (approximately $1.77M) with zero outflows observed as of the investigation date. This pattern is consistent with either a cryptocurrency exchange deposit wallet, a mixing or coinjoin-style service, or simply a personal consolidation wallet belonging to the threat actor — however, Arkham Intelligence's free-tier lookup returns no entity label or exchange tag for the address, leaving its true nature unresolved by publicly available tools. August 7-8, 2026: Trezor publishes a broader public advisory warning of a general rise in phishing websites impersonating its brand via sponsored search placements, and CryptoTimes separately reports the underlying campaign may have affected as many as 80 total victims — a figure that could plausibly reflect either the 80 individual transactions received from the single confirmed victim, or a wider, multi-victim campaign scope; this ambiguity has not been definitively resolved as of the reporting window's close. No arrests, fund recovery, or attacker identification have been publicly confirmed.
Sources and coverage
- Articlex.comhttps://x.com/ReallyBadDay99/status/2085454877719675354
- Articlex.comhttps://x.com/Trezor/status/2085681844599546144
- Articlecrypto.newshttps://crypto.news/trezor-user-life-savings-stolen-via-google-phishing-ad/
- Articlecryptotimes.iohttps://www.cryptotimes.io/2026/08/08/trezor-phishing-site-on-google-claims-80-victims/
- Articletech.yahoo.comhttps://tech.yahoo.com/cybersecurity/articles/trezor-phishing-ad-btcpay-exploit-173555984.html
- Articlemempool.spacehttps://mempool.space/address/bc1qrz33mr7tx8wrpcs2pxrvv83hqwpm907s9shkz4
Victim testimonies
No testimonies yet.
+ Add my testimony → (coming soon)