A phishing site disguised as Trezor surfaced as the top Google search result this week, and users who clicked through had their crypto wallets drained. The fraudulent page, which mimicked the hardware wallet maker's official site, appeared ahead of the real Trezor domain in search results, catching victims before they realized the address was wrong.
How the Scam Worked
The fake site was designed to look nearly identical to Trezor's login and recovery page. Visitors were prompted to enter their recovery seed phrase — the same 12 or 24 words that control access to a hardware wallet. Once entered, the information went straight to the scammers, who used it to empty the associated accounts.
Because the page ranked first on Google, many users never questioned its authenticity. Search engines are often the first stop for people trying to reach a service, and a top result carries an implicit trust that scammers are increasingly exploiting.
The Ad Screening Problem
The incident highlights a persistent gap in how search platforms vet sponsored content. The phishing page appeared in the paid results section, meaning it got its top spot through advertising rather than organic ranking. That raises pointed questions about the checks that are supposed to catch fraudulent domains before they go live.
Google has long faced criticism for allowing malicious ads to slip through its review process. While the company has automated filters and human moderators, bad actors continually find ways to evade them — often by rotating domains, using lookalike URLs, or tweaking landing pages after approval.
Why User Vigilance Still Matters
For Trezor users, the takeaway is simple: always double-check the URL before entering any sensitive information. The official domain is trezor.io, and it rarely changes. A single missing letter or a swapped TLD is a red flag.
Security experts routinely advise people to type the address directly into their browser instead of clicking search results. Bookmarks help too. The extra few seconds can mean the difference between keeping your funds and losing them.
This is not the first time a crypto-related phishing page has ranked highly on Google, and it won't be the last. The burden currently falls on users to stay alert, because the platforms responsible for ad screening are still playing catch-up.
Affected users are urged to move any remaining funds to a fresh wallet immediately and to treat the compromised seed phrase as permanently exposed. Trezor has not yet issued a public statement about this specific incident, but the company has previously warned customers about phishing attempts and provided guidance on how to spot them.
What Comes Next
The search giant has not announced any new measures in response to this incident. Whether Google tightens its ad review process remains an open question. For now, the safest bet is to ignore search results entirely when it comes to crypto services — go straight to the source, and never enter your recovery phrase anywhere except the hardware device itself.




