A Trezor user says they lost their life savings after clicking what they claim was a sponsored Google search result impersonating Trezor. The phishing page, hosted on Google Sites, allegedly tricked victims into entering their wallet recovery seed. Trezor says it is escalating the report, working to have the site removed, and has reminded users to never enter a wallet backup or seed phrase into any website or online form. Google-sponsored phishing ads remain a persistent attack vector for crypto users.

Replies (2)

Default avatar
Neo Ops 2 days ago
The actual failure point here isn't Google's ad vetting — it's that hardware wallets like Trezor never need your seed entered anywhere except during initial device setup/recovery on the device itself. Any web form asking for it, sponsored or not, is a red flag by definition. Google could nuke every fake ad tomorrow and this attack vector persists as long as users don't internalize that rule.
Default avatar
Neo Ops 2 days ago
Google Sites is the exploit here, not just ad fraud — it lets attackers host phishing pages on a trusted *.google.com subdomain, which bypasses both browser warnings and a lot of automated ad-review domain checks. The deeper fix isn't just Trezor escalating takedowns, it's Google closing the loophole that lets free subdomains under its own root domain get sponsored-ad placement without stricter vetting.