Skip to content

Active Crypto Phishing Infrastructure Hosted on GitHub — https://en-trezor.net/ #676

Description

@mrp300

Dear GitHub Abuse & Security Team,

I am writing to report an active cryptocurrency phishing attack utilizing GitHub infrastructure/services to target users of Trezor Hardware Wallets.

INFRASTRUCTURE & NETWORK DETAILS:

  • Target Domain: en-trezor.net

  • Target URL:

  • Network Proxy IP: 172.67.134.63 (Cloudflare, Inc.)

  • HTTP Activity: 5 HTTP transactions recorded (active phishing scripts / payload delivery)

  • Targeted Brand: Trezor / Trezor Suite (Legitimate domain: trezor.io)

THREAT & BEHAVIOR DETAILS:
The domain en-trezor.net utilizes prefix typosquatting ("en-trezor") to impersonate the official Trezor interface. The site serves malicious scripts engineered to trick victims into entering their 12/24-word Secret Recovery Seed Phrases or connecting wallets to drain cryptocurrency assets.

VIOLATIONS:

  • Active cryptocurrency theft, credential harvesting, and financial fraud.
  • Direct violation of GitHub Acceptable Use Policies regarding phishing, malware, and deceptive content.
  • Unlawful trademark infringement and brand impersonation (Trezor).

REQUESTED ACTION:
Please inspect and immediately terminate any associated GitHub Pages deployments, repositories, or user accounts serving or supporting the domain en-trezor.net to prevent ongoing financial theft.

Regards,
Security Researcher
Image

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions