📅 Senin, 10 Agustus 2026 · --:-- WIB Ikuti kami
Ecosystem
ID
Tabungan Seumur Hidup Lenyap Usai Klik Iklan Google - Ironinya Situs Phishing Ini Bersarang di Platform Tepercaya

Lifetime Savings Vanished After Clicking Google Ad - Ironically, This Phishing Site Was Hosted on a Trusted Platform

A crypto user named David with the X account @ReallyBadDay99 recently reported losing his entire lifetime savings on August 7. Instead of being hacked through a complex smart contract code exploit, David was tricked after clicking on a Google paid search result impersonating Trezor.

The fake ad directed him straight to a phishing page. To make it more convincing and avoid getting blocked, the hacker hosted their trap page on the trusted platform Google Sites. David has now shared the attacker’s wallet address with on-chain investigator ZachXBT and security firm CertiK. He claims that the attacker’s wallet address has already drained millions of dollars from many other victims who suffered the same fate.

Hiding Behind Big Names

Leveraging established services is a key tactic of this group. By piggybacking on the Google Sites platform, their phishing page appears safer and more legitimate to many users. Users who are usually wary of strange domains often let their guard down when the web address is hosted under the banner of a major service provider.

A few hours after David’s report circulated widely, Trezor finally issued an official warning to all of their users. The hardware wallet company confirmed that they are seeing an increase in phishing websites specifically designed to mimic their platform.

Trezor warned that some of these fake websites are deliberately placed to appear at the top of paid search engine results, making them look convincing to both new and existing users. Responding to this, Trezor reiterated the most fundamental rule of storing digital assets: “Never enter your wallet backup on a website or share it with anyone.”

An Old Tactic that Continues to Claim Victims

The modus operandi of using search engine advertisements to steal crypto assets is nothing new in this industry. Last May, a similar method was deployed when a series of fake Uniswap ads ran on Google Search. The malicious campaign drained at least $400,000 from several users who did not realize they were entering a clone site.

Long before the Uniswap case, records from the Security Alliance also showed a worrying trend. They documented losses of approximately $1.27 million purely stemming from clicks on malicious Google ads in just a short window of time between March 13 and 30.

This form of phishing attack also continues to evolve. While cybercriminals are currently aggressively using paid digital ads, last February fraudsters opted for a conventional method. They sent fake physical letters impersonating Trezor and Ledger to users’ home addresses. The letters contained a QR code that ultimately directed scanners to a phishing website.

The incident that befell David’s savings highlights the fundamental reality of self-custody. Layer upon layer of protection on even the most robust hardware will not function if the owner themselves hands over their master key on a fake site. Clicking on search engine ads now demands the same high level of caution as signing high-value transactions.

Reported by crypto.news.


Disclaimer: This article is for informational and educational purposes only, not financial advice. Cryptocurrency assets are highly volatile and carry significant risk. Always do your own research (DYOR) and never invest more than you can afford to lose.

Bagikan artikel ini:
📩 KABAR BITCOIN 1 MENIT

Berita kripto harian, langsung ke inbox

Ringkasan 1 menit untuk kamu yang selalu bergerak. Gratis, kapan saja bisa berhenti.

Total
0
Share