New Registrations
Trezor phishing domains
Newly registered lookalikes - tracked daily
Trezor phishing domains
Newly registered lookalikes - tracked daily
Tracked (7d)
26
New (24h)
11
vs avg
—
Recently registered domains — may be used for phishing. Screenshots show parking pages while domains warm up. Use for Threat Hunting or watchlists.
| Last check (UTC) | First seen (UTC) ▾ | URL | Screenshot | Flags | Details |
|---|---|---|---|---|---|
| 2026-08-25 01:33 | 2026-08-25 01:33 | ![]() |
Details | ||
| 2026-08-25 01:33 | 2026-08-25 01:33 | ![]() |
Details | ||
| 2026-08-25 01:33 | 2026-08-25 01:33 | ![]() |
Details | ||
| 2026-08-25 01:32 | 2026-08-25 01:32 | ![]() |
Details | ||
| 2026-08-24 01:46 | 2026-08-24 01:46 | ![]() |
Details | ||
| 2026-08-24 01:44 | 2026-08-24 01:44 | ![]() |
Details | ||
| 2026-08-24 01:44 | 2026-08-24 01:44 | ![]() |
Details | ||
| 2026-08-24 01:43 | 2026-08-24 01:43 | ![]() |
Details | ||
| 2026-08-24 01:35 | 2026-08-24 01:35 | ![]() |
Details | ||
| 2026-08-24 01:14 | 2026-08-24 01:14 | ![]() |
Details | ||
| 2026-08-24 01:09 | 2026-08-24 01:09 | ![]() |
Details | ||
| 2026-08-23 02:34 | 2026-08-23 02:34 | ![]() |
Details | ||
| 2026-08-23 02:33 | 2026-08-23 02:33 | ![]() |
Details | ||
| 2026-08-22 02:49 | 2026-08-22 02:49 | ![]() |
Details | ||
| 2026-08-21 02:46 | 2026-08-21 02:46 | ![]() |
Details | ||
| 2026-08-21 02:46 | 2026-08-21 02:46 | ![]() |
OpenPhish | Details | |
| 2026-08-21 02:46 | 2026-08-21 02:46 | ![]() |
Details | ||
| 2026-08-21 01:16 | 2026-08-21 01:16 | ![]() |
Details | ||
| 2026-08-21 00:59 | 2026-08-21 00:59 | ![]() |
Details | ||
| 2026-08-20 02:39 | 2026-08-20 02:39 | ![]() |
Details | ||
| 2026-08-20 02:39 | 2026-08-20 02:39 | ![]() |
OpenPhish | Details | |
| 2026-08-20 02:38 | 2026-08-20 02:38 | ![]() |
Details | ||
| 2026-08-18 02:06 | 2026-08-18 02:06 | ![]() |
Details | ||
| 2026-08-18 02:05 | 2026-08-18 02:05 | ![]() |
Details | ||
| 2026-08-18 02:05 | 2026-08-18 02:05 | ![]() |
Details | ||
| 2026-08-18 00:51 | 2026-08-18 00:51 | ![]() |
Details |
Recently registered domains — may be used for phishing. Screenshots show parking pages while domains warm up. Use for Threat Hunting or watchlists.
| URL | Screenshot | Details |
|---|---|---|
| https://trezors.net
|
![]() |
Details |
| https://trezor.ltda
|
![]() |
Details |
| https://trezoclub.com
|
![]() |
Details |
| https://suite-trezor.net
|
![]() |
Details |
| https://v2-trezor.org
|
![]() |
Details |
| https://trezorsuite.report
|
![]() |
Details |
| https://trezordevicefix.com
|
![]() |
Details |
| https://trezor-app-web.com
|
![]() |
Details |
| https://psina-trezor.art
|
![]() |
Details |
| https://en-trezor-io.org
|
![]() |
Details |
| https://delink-trezor.com
|
![]() |
Details |
| https://trezor.stream
|
![]() |
Details |
| https://trezor-en.org
|
![]() |
Details |
| https://trezor-nl.com
|
![]() |
Details |
| https://trezova.com
|
![]() |
Details |
| https://trezorsuitev2.com
OpenPhish |
![]() |
Details |
| https://trezorsuite-s3.org
|
![]() |
Details |
| https://confirm-trezor.com
|
![]() |
Details |
| https://account-safety-trezor…
|
![]() |
Details |
| https://trezorios.com
|
![]() |
Details |
| https://trezor.rest
OpenPhish |
![]() |
Details |
| https://trezor.mobi
|
![]() |
Details |
| https://trezour-site-web.com
|
![]() |
Details |
| https://trezorwallet.dev
|
![]() |
Details |
| https://trezor-device.support
|
![]() |
Details |
| https://account-security-trez…
|
![]() |
Details |
AIHow to verify a real Trezor URL
- Legitimate Trezor URLs always end in
trezor.io(e.g.www.trezor.io,account.trezor.io). Anything else — including look-alike typosquats, hyphenated variations, or unfamiliar TLDs like.xyz/.top/.vip— is not Trezor. - The domains listed above were registered within the last 7 days. New-domain age is itself a signal — Trezor has owned
trezor.iofor years; brand-new look-alikes are almost never legitimate. - If you got the link from email, SMS, or social media, do not click it. Open
trezor.iofrom your browser bookmark or type the domain manually. - Real Trezor pages almost never ask for credentials immediately after clicking from a message — treat any such redirect as a phishing attempt until the domain is verified.


















