
A fraudulent Trezor phishing site appeared as the top Google sponsored search result on August 7, 2026, successfully tricking users into entering their wallet recovery phrases. According to latest reports, the fake page was hosted on Google Sites at a URL beginning with sites.google.com/view/start-trezor-suite, which lent it an air of legitimacy that a random domain wouldn't have carried. The phishing page closely mimicked Trezor's legitimate interface, prompting users to enter their 12- or 24-word recovery phrases - the master keys to their crypto wallets. As reported by multiple sources, at least one victim lost their entire life savings in this attack, though the specific value of losses and total amount stolen from other users has not been independently verified.
Trezor confirmed it is aware of the incident and is working internally to escalate the matter, with the company stating it is collaborating with Google to get the fraudulent ad removed. The company has reminded users of a cardinal rule in crypto security: 'Never share your seed phrase with anyone or any website, ever.' Trezor's response did not confirm the specific loss amount reported by victim David, nor did it identify the operators of the reported phishing page, but the company's proactive collaboration with Google demonstrates increased awareness of the threat. Trezor also did not say whether the specific Google Sites page identified in David's post had been removed.
According to the latest reports, a wallet recovery phrase gives its holder control over the associated cryptocurrency. If a victim enters the phrase on a fraudulent website, an attacker can restore the wallet on another device and transfer its assets without access to the original hardware wallet. Blockchain transactions are generally irreversible, leaving victims with few options after funds have been transferred. The reported Trezor page being hosted on Google Sites reflects a tactic where attackers use trusted online services to make fraudulent pages appear safer, with the sponsored search result positioning making the attack particularly dangerous as it appeared above legitimate results.
Google acknowledged in a June fraud advisory that scammers were abusing reputable cloud platforms to host phishing content and bypass security filters. The latest incident demonstrates how paid search ad fraud targeting crypto users has become a recurring problem throughout 2025 and 2026. In May 2026, a similar scheme involving fake Uniswap sites reportedly cost users more than $400,000, highlighting the escalating threat to cryptocurrency holders. The continued use of Google's advertising and hosting infrastructure makes the threat relevant to U.S. cryptocurrency holders who depend on search results to access wallet services, with no U.S. regulator or law-enforcement agency having publicly announced an investigation into the reported losses.
For crypto users, the defensive playbook remains unchanged despite the latest incident. Bookmark official sites rather than searching for them, as sponsored search results appear above organic ones and well-funded attackers can literally outrank legitimate companies. Never enter a recovery phrase into any website, as legitimate wallet providers will never ask for your seed phrase through a web form. Treat sponsored search results with deep skepticism, especially for anything involving financial products, and remember that a legitimate wallet provider will never, under any circumstances, ask for your seed phrase through a web form. The uncomfortable question raised by this incident is about Google's ad screening process, as a phishing page impersonating a well-known financial product made it through whatever review mechanisms exist and landed in the single most visible position on search results.