trezor-help[.]support
Phishing and security check for trezor-help.support
“Trezor Wallet Recovery”
PhishDestroy first observed trezor-help.support on Jun 15, 2026. Evidence score: 100/100 (a triage score, not a probability).
Threat signals: 22 of 91 VirusTotal engines flagged the domain on Jul 18, 2026 at 18:45 UTC. External blocklists: 2 matches (MetaMask, SEAL) in the snapshot from Aug 6, 2026 at 10:20 UTC. AlienVault OTX recorded 2 community pulse references on Jun 15, 2026 at 22:16 UTC. Cloudflare Radar classified the domain as malicious; no source timestamp was recorded.
The latest probe returned HTTP 404 on Aug 6, 2026 at 10:15 UTC, so content was unavailable at the checked location. This does not establish the cause.
Other observations: Google Safe Browsing recorded no flag on Jun 25, 2026 at 10:30 UTC. Spamhaus DBL recorded no positive result on Jul 15, 2026 at 22:30 UTC. URLScan captured the domain on Jun 15, 2026 at 17:19 UTC. Negative or missing results do not establish safety.
Context: registrar Name.com, Inc., IP address 34.111.179.208, registration date Jun 15, 2026, apparent target Trezor. Infrastructure details may have changed since collection.
This report summarizes time-bound observations, not a live guarantee. Avoid interacting with the domain; submit an appeal if the report is inaccurate.
Network Security Intelligence
Threat Response Pipeline
Public Blocklist Status
Stored Capture
Domain Intelligence
Technical detailsDNS, SSL SANs, timestamps
ICANN OVERSIGHT
Accreditation and RAA context
Accreditation and RAA context
ICANN Got Paid. Accountability Did Not Arrive.
For this gTLD, the registrar above operates under an ICANN contract. ICANN collects annual, variable and transaction-based fees tied to registrations, renewals and transfers.
Accreditation: monetized. Accountability: please check back later.
Then the magic starts: ICANN writes RAA §3.18, the registrar investigates abuse inside its own customer base, and victims deliver the evidence for free while every layer waits for someone else to act. If that makes victims feel safer, excellent—the invoice worked.
Technologies · 7 identified
Node.js is an open-source, cross-platform, JavaScript runtime environment that executes JavaScript code outside a web browser.
nodejs.org 100% confidenceExpress is a web application framework for Node.js, released as free and open-source software under the MIT License. It is designed for building web applications and APIs.
expressjs.com 100% confidenceHTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS.
www.rfc-editor.org 100% confidenceGoogle Cloud Trace is a distributed tracing system that collects latency data from applications and displays it in the Google Cloud Console.
cloud.google.com 100% confidenceCloud CDN uses Google's global edge network to serve content closer to users.
cloud.google.com 100% confidenceHTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org 100% confidenceVirusTotal Analysis
Evidence & External Reports
“The domain is a live, recently registered site that presents itself as Trezor and uses wallet-recovery language aimed at crypto users. The page includes calls to recover a wallet using a recovery phrase, which is consistent with seed-phrase harvesting and phishing behavior rather than legitimate support content. The domain is independently registered and hosted, so removal of the hosted content plus registrar suspension is warranted; internal blocklisting is also appropriate to reduce exposure w”
Were You Affected by This Site?
If you entered account credentials, personal or payment information, or downloaded a file from this domain, take immediate action. Below are resources to help you report the incident and protect yourself.
Report to Your Local Authorities
Select your country to get official cybercrime contacts, or create a complaint draft →.
About This Report: trezor-help.support
This report presents the latest stored evidence available to PhishDestroy. Source timestamps are shown where available; availability and vendor verdicts can change after collection.
The captured site displayed the page title “Trezor Wallet Recovery” and may be impersonating Trezor.
As of Aug 6, 2026, trezor-help.support had detections from 22 security engines.
If you believe this listing is inaccurate, submit an appeal. To learn about our methodology, visit the FAQ page.
Check Any Domain
Threat analysis using stored blocklist, WHOIS, DNS, and public scan evidence
Scan NowReport Phishing
Submit suspicious domains to our threat database — protect the community
ReportLive Threat Feed
Recent phishing reports and observed availability changes
MonitorStay Informed, Stay Safe
Monitor live threats or contest this listing if you believe it's a false positive