trezor-backup[.]io
“Suspected Phishing | Cloudflare”
Evidence Summary
Analysis of trezor-backup.io indicates that the domain is currently active and classified as a crypto drainer, a threat that seeks to compromise cryptocurrency wallets or extract private keys. The domain appears on a single security blocklist and is explicitly blocked by the PhishDestroy service, suggesting that at least one reputable threat‑intelligence feed has flagged it for malicious activity. VirusTotal scanning reports that one out of ninety‑one security vendors returned a positive detection for the domain, providing additional corroboration of its suspicious nature.
No further reconnaissance data such as registrar details, IP address, hosting provider, SSL certificate information, HTTP response codes, Safe Browsing status, or Open Threat Exchange (OTX) entries were supplied, leaving the underlying infrastructure largely opaque. Consequently, the precise hosting environment, geographic location, and any associated malicious payloads cannot be confirmed at this time. Defenders should treat the domain as high‑risk given its elevated risk rating and active status.
Recommended mitigation steps include adding trezor-backup.io to network and endpoint deny‑lists, enforcing DNS filtering policies to block resolution, and monitoring outbound traffic for attempts to contact the domain. Continuous re‑evaluation is advised, as additional intelligence—such as detection signatures from more vendors, TLS certificate data, or observed command‑and‑control communications—may emerge and refine the threat profile. Organizations should also educate users about the danger of unsolicited requests for cryptocurrency seed phrases, reinforcing the principle that legitimate services never ask for private keys via unsolicited links.
Data Coverage
Threat Response Pipeline
Blocklist coverage
10 monitored external feeds · stored snapshot Aug 11, 2026
10 monitored external feeds No match
Detection timeline
-
Domain status
Reachable → Unreachable
-
Domain status
Unreachable → Reachable
Community reports
Reported by 0 community members, first seen Aug 2, 2026
- Unique reported URLs
- 1
Community intelligence
1 community report
CategoryIMPERSONATION
Brand abuse: phishing, impersonation, impersonating Trezor
Technologies
3 high-confidence technologies identified
VirusTotal Analysis
Site Performance Analysis
Google PageSpeed Insights — mobile performance audit of trezor-backup.io · checked Aug 2, 2026
Lookalike domains
74 stored lookalike domains
Show all (62)
Were You Affected by This Site?
If credentials, payment data, or files were exposed, report the incident immediately. Change affected passwords, revoke active sessions, and scan the device.
Report to Your Local Authorities
Select your country to get official cybercrime contacts, or create a complaint draft →.
Check Any Domain
Threat analysis using stored blocklist, WHOIS, DNS, and public scan evidence
Scan NowReport Phishing
Submit suspicious domains to our threat database — protect the community
ReportLive Threat Feed
Recent phishing reports and observed availability changes
MonitorStay Informed, Stay Safe
Monitor live threats or contest this listing if you believe it's a false positive