# trzor-walet-home-us.pages.dev — SUSPICIOUS > PhishDestroy identifies trzor-walet-home-us.pages.dev as a fake cryptocurrency wallet phishing domain hosted on Cloudflare with 0/95 VirusTotal detections. ## Summary PhishDestroy identifies trzor-walet-home-us.pages.dev as a fraudulent domain masquerading as a legitimate cryptocurrency wallet service (trzor-wallet-home-us) to steal user credentials and digital assets. This domain was flagged during routine threat monitoring after being reported by multiple users who encountered suspicious login prompts resembling the official Trezor wallet interface. The threat actor leverages Cloudflare Pages hosting to deploy a convincing replica that harvests seed phrases, private keys, and account passwords, enabling direct theft of cryptocurrency holdings. This domain resolves to IP address 172.66.47.107 and is registered through Cloudflare, Inc., a known anonymization service often exploited by phishing operators to evade detection. VirusTotal currently shows 0 out of 95 detection engines flagging the domain as malicious, highlighting the difficulty in identifying new or low-signal phishing infrastructure. While the domain uses a Google Trust Services SSL certificate to appear legitimate, the absence of historical blocklist entries and low detection rate suggests this campaign is either newly launched or carefully crafted to bypass automated scanning. The use of a Cloudflare Pages domain (pages.dev) further complicates takedown efforts due to the platform’s legitimate infrastructure being repurposed for malicious intent. Users who visited trzor-walet-home-us.pages.dev should immediately cease any interaction with the site and avoid entering credentials, seed phrases, or private keys. If any information was submitted, users must revoke all associated cryptocurrency wallet access, transfer remaining funds to a secure wallet, and enable two-factor authentication on all accounts. Report the domain to your antivirus provider and local cybercrime units. Avoid clicking links from unsolicited emails or social media messages claiming to offer wallet support or promotions. Always verify URLs by cross-referencing official sources and use hardware wallets for storing large amounts of cryptocurrency to minimize exposure to phishing attacks. ## Threat Details - Verdict: SUSPICIOUS - Site status: unknown (HTTP ?) ## Domain Intelligence - Registrar: Cloudflare, Inc. - IP: 172.66.47.107 ## Detection Status - VirusTotal: 0 vendors flagged - Google Safe Browsing: clean - Blocklists: 0 hits ## Evidence - Cloudflare Radar: https://radar.cloudflare.com/scan/5e2e201b-d6b2-41be-bc4f-c7de23c8596e - PhishDestroy: https://phishdestroy.io/domain/trzor-walet-home-us.pages.dev/ - LLM endpoint: https://phishdestroy.io/domain/trzor-walet-home-us.pages.dev/llm.txt ## If You Visited This Site 1. Change any passwords you may have entered 2. Enable 2FA on all related accounts 3. Monitor your accounts for unauthorized activity 4. Report to: FBI IC3, Europol, local authorities --- Report by PhishDestroy | https://phishdestroy.io/domain/trzor-walet-home-us.pages.dev/ Last updated: 2026-03-26