io-trezo-bridge[.]pages[.]dev
“tnamp.d1zbww9y4cvvrf.amplifyapp.com”
Zusammenfassung der Beweislage
This domain, io-trezo-bridge.pages.dev, is identified as an active cryptocurrency wallet phishing site targeting users of the Trezor hardware wallet. Analysis indicates the domain is designed to harvest sensitive credentials, including private keys, recovery phrases, and wallet login details, under the guise of a legitimate bridge or authentication service. The domain remains operational as of the latest verification and poses a high risk to individuals interacting with cryptocurrency storage solutions. Infrastructure analysis reveals the domain was registered through Cloudflare, Inc. on September 03, 2025, and resolves to the IP address 188.114.96.3, associated with AS13335 (Cloudflare, Inc.) in the United States. The SSL certificate is issued by Google Trust Services (WE1), a common feature in both legitimate and malicious domains. Security telemetry shows the domain is flagged by 1 of 95 vendors on VirusTotal, while appearing on three independent security blocklists. Additional technical indicators include the page title tnamp.d1zbww9y4cvvrf.amplifyapp.com, suggesting a possible link to a compromised or misconfigured subdomain used to host phishing content. Current status confirms the domain remains active and continues to serve phishing content. Organizations and individuals are advised to block access to io-trezo-bridge.pages.dev at the network level and update endpoint protection rules to include this domain. Users who may have interacted with the site should immediately revoke any permissions granted, rotate all credentials, and transfer assets to a new wallet. Monitoring for unauthorized transactions and enabling multi-factor authentication on all related accounts is strongly recommended. Security teams should treat this domain as a high-priority threat and include it in threat intelligence feeds for proactive defense.
Data Coverage
Erkenntnisse zur Netzwerksicherheit
Pipeline zur Reaktion auf Sicherheitsbedrohungen
Blocklistenabdeckung
10 überwachte externe Feeds · gespeicherter Stand 11.08.2026
Domain-Intelligenz
Technische DetailsDNS, TLS-Namen und Zeitstempel
VirusTotal-Analyse
Wurden Sie von dieser Website betroffen?
Wenn Sie Kontoanmeldeinformationen, persönliche oder Zahlungsinformationen eingegeben oder eine Datei von dieser Domain heruntergeladen haben, ergreifen Sie sofort Maßnahmen. Nachfolgend finden Sie Ressourcen, die Ihnen helfen, den Vorfall zu melden und sich zu schützen.
Melden Sie sich bei Ihren örtlichen Behörden
Wählen Sie Ihr Land aus, um Offizielle Kontakte im Bereich Cyberkriminalität oder einen Beschwerdeentwurf erstellen → zu erhalten.
Jede beliebige Domain prüfen
Bedrohungsanalyse anhand gespeicherter Blocklisten, WHOIS, DNS und öffentlicher Scan-Beweise
Jetzt scannenPhishing melden
Melden Sie verdächtige Domains an unsere Bedrohungsdatenbank – schützen Sie die Community
MeldenEchtzeit-Bedrohungsfeed
Aktuelle Phishing-Meldungen und beobachtete Verfügbarkeitsänderungen
ÜberwachenBleiben Sie auf dem Laufenden, bleiben Sie sicher
Beobachten Sie aktuelle Bedrohungen oder legen Sie Widerspruch gegen diesen Eintrag ein, wenn Sie der Meinung sind, dass es sich um einen Fehlalarm handelt