Suspicious
Phishings targeting Trezor
Suspicious and active websites
Phishings targeting Trezor
Suspicious and active websites
Active
10
New (7d)
3
Trend (7d)
—
Suspicious sites — confidence is not always 100%. Use for Threat Hunting or watchlists.
| Last check (UTC) | First seen (UTC) ▾ | URL | Screenshot | Flags | Details |
|---|---|---|---|---|---|
| 2026-10-04 03:30 | 2026-10-03 01:03 | ![]() |
OpenPhish | Details | |
| 2026-10-04 03:30 | 2026-10-02 13:03 | ![]() |
OpenPhish | Details | |
| 2026-10-04 03:30 | 2026-09-27 04:01 | ![]() |
PhishTank | Details | |
| 2026-10-04 03:30 | 2026-09-26 13:03 | ![]() |
OpenPhish | Details | |
| 2026-10-04 03:30 | 2026-09-25 13:07 | ![]() |
OpenPhish | Details | |
| 2026-10-04 03:30 | 2026-09-20 01:02 | ![]() |
OpenPhish | Details | |
| 2026-10-04 03:30 | 2026-09-02 13:04 | ![]() |
OpenPhish | Details | |
| 2026-10-04 03:30 | 2026-08-26 01:02 | ![]() |
OpenPhish urlscan | Details | |
| 2026-10-04 03:30 | 2026-08-13 13:02 | ![]() |
OpenPhish urlscan | Details | |
| 2026-10-04 03:30 | 2026-08-07 01:01 | ![]() |
OpenPhish | Details |
Suspicious sites — confidence is not always 100%. Use for Threat Hunting or watchlists.
| URL | Screenshot | Details |
|---|---|---|
| https://startio-trexor.square…
OpenPhish |
![]() |
Details |
| https://start-faq-en-trezr--p…
OpenPhish |
![]() |
Details |
| https://trezoorr--thego.gitbo…
PhishTank |
![]() |
Details |
| https://trezorrgoappup.gitboo…
OpenPhish |
![]() |
Details |
| https://trezoriostart-web.squ…
OpenPhish |
![]() |
Details |
| http://trezorwollet.webador.c…
OpenPhish |
![]() |
Details |
| https://trezorguide.vercel.app
OpenPhish |
![]() |
Details |
| https://docs-trezor-app.pages…
OpenPhish urlscan |
![]() |
Details |
| https://web-trezor-io-start-u…
OpenPhish urlscan |
![]() |
Details |
| http://trezor-login-us-auth-s…
OpenPhish |
![]() |
Details |
AIHow to verify a real Trezor URL
- Legitimate Trezor URLs always end in
trezor.io(e.g.www.trezor.io,account.trezor.io). Anything else — including look-alike typosquats, hyphenated variations, or unfamiliar TLDs like.xyz/.top/.vip— is not Trezor. - The padlock icon proves TLS is active, not that the site is safe. Free DV certificates are issued to attackers in minutes; every active site listed above has a valid TLS certificate.
- If you got the link from email, SMS, or social media, do not click it. Open
trezor.iofrom your browser bookmark or type the domain manually. - Real Trezor pages almost never ask for credentials immediately after clicking from a message — treat any such redirect as a phishing attempt until the domain is verified.









