# trezrr----walltt.pages.dev — SUSPICIOUS > Domain trezrr----walltt.pages.dev is a live Trezor wallet phishing site flagged by 2/95 VirusTotal scanners. Check the full report. ## Summary PhishDestroy identifies an active cryptocurrency phishing campaign targeting Trezor wallet users via the domain trezrr----walltt.pages.dev. This fraudulent site mimics the official Trezor wallet interface to trick victims into entering seed phrases, which are immediately harvested by attackers to drain cryptocurrency holdings. The page is hosted on Cloudflare Pages and has not been taken down despite its malicious activity, posing an elevated ongoing risk to unsuspecting users. Anyone who visits this domain could lose funds within minutes if they enter credentials or seed phrases. This domain was flagged by 2 out of 95 VirusTotal security vendors and resolves to IP address 188.114.96.3. It uses a Google Trust Services SSL certificate to appear legitimate. The domain was registered through Cloudflare, Inc., which has not suspended the page despite the confirmed malicious activity. Cloudflare Pages is commonly abused by threat actors to host phishing kits quickly and evade traditional takedown processes. If you visited trezrr----walltt.pages.dev, immediately cease using any cryptocurrency wallets on the same device. Do not enter any seed phrases, passwords, or recovery keys on this site. Disconnect the device from the internet and run a full antivirus scan. Consider transferring remaining funds to a newly created wallet with a different seed phrase. Report the domain to your antivirus provider and to Google Safe Browsing at safebrowsing.google.com/report_phish. Monitor your cryptocurrency accounts closely for unauthorized transactions. ## Threat Details - Verdict: SUSPICIOUS - Site status: unknown (HTTP ?) ## Domain Intelligence - Registrar: Cloudflare, Inc. - IP: 188.114.96.3 ## Detection Status - VirusTotal: 2 vendors flagged - Google Safe Browsing: clean - Blocklists: 0 hits ## Evidence - Cloudflare Radar: https://radar.cloudflare.com/scan/da34ecff-431b-4056-9fe6-4822ab81731b - PhishDestroy: https://phishdestroy.io/domain/trezrr----walltt.pages.dev/ - LLM endpoint: https://phishdestroy.io/domain/trezrr----walltt.pages.dev/llm.txt ## If You Visited This Site 1. Change any passwords you may have entered 2. Enable 2FA on all related accounts 3. Monitor your accounts for unauthorized activity 4. Report to: FBI IC3, Europol, local authorities --- Report by PhishDestroy | https://phishdestroy.io/domain/trezrr----walltt.pages.dev/ Last updated: 2026-03-22