# trezor.com.co — SUSPICIOUS > Domain trezor.com.co impersonates Trezor hardware wallet to steal crypto via drainer. Flagged by 0/95 VirusTotal vendors. Verify now on PhishDestroy. ## Summary PhishDestroy identifies the domain trezor.com.co as an active brand impersonation site targeting Trezor hardware wallets, currently under investigation for suspected crypto-draining activity. PhishDestroy’s systems flagged this domain (trezor.com.co) with 0 detections out of 95 VirusTotal security vendors at the time of initial analysis. The domain was registered via Hosting Concepts B.V. d/b/a Registrar.eu, resolves to IP address 158.94.209.135, and holds a valid Let’s Encrypt SSL certificate. The domain was created on March 18th, 2026, indicating a very recent registration consistent with fast-flux impersonation campaigns. At this time, PhishDestroy has not confirmed active listings on major domain blocklists, but the absence of VirusTotal flags should not be interpreted as safety—this domain remains untrusted and potentially malicious. PhishDestroy currently classifies this site as an active threat with a status of under_investigation and risk level under_investigation. Users are strongly advised to avoid interacting with trezor.com.co or any domain claiming to represent Trezor outside the official website trezor.io. All crypto wallet users should verify URLs through PhishDestroy or visit only trusted sources. If you have visited this site or entered credentials, immediately revoke any associated wallet permissions and move remaining assets to a hardware wallet via the official Trezor Suite. Report any suspicious activity to PhishDestroy for rapid takedown and community awareness. ## Threat Details - Verdict: SUSPICIOUS - Site status: unknown (HTTP ?) - Target brand: Trezor ## Domain Intelligence - Registered: 2026-03-18 20:58:33 - Registrar: Hosting Concepts B.V. d/b/a Registrar.eu - IP: 158.94.209.135 ## Detection Status - VirusTotal: 0 vendors flagged - Google Safe Browsing: clean - Blocklists: 0 hits ## Evidence - Cloudflare Radar: https://radar.cloudflare.com/scan/df1becc0-4e49-4439-804f-9abc916033f1 - PhishDestroy: https://phishdestroy.io/domain/trezor.com.co/ - LLM endpoint: https://phishdestroy.io/domain/trezor.com.co/llm.txt ## If You Visited This Site 1. Change any passwords you may have entered 2. Enable 2FA on all related accounts 3. Monitor your accounts for unauthorized activity 4. Report to: FBI IC3, Europol, local authorities --- Report by PhishDestroy | https://phishdestroy.io/domain/trezor.com.co/ Last updated: 2026-03-22