Dear Abuse & Security Team,
I am writing to submit an urgent phishing report regarding an active malicious domain registered under the .ORG TLD targeting Trezor Hardware Wallet users.
INFRASTRUCTURE DETAILS:
- Target Phishing Domain: en-trezor.org
- Target URL: https://en-trezor.org/
- Impersonated Brand: Trezor / Trezor Suite (Legitimate domain: trezor.io)
- Active Host/Proxy: Cloudflare, Inc.
THREAT DETAILS:
The domain en-trezor.org employs brand spoofing and prefix typosquatting ("en-trezor") to impersonate the official Trezor interface. The site is engineered to deceive victims into entering their 12/24-word Secret Recovery Seed Phrases or connecting wallets to drain cryptocurrency assets.
VIOLATIONS:
- Active cryptocurrency theft and credential harvesting.
- Unlawful trademark infringement and brand impersonation (Trezor).
- Direct violation of PIR (.ORG Registry) and Cloudflare Acceptable Use Policies (AUP).
REQUESTED ACTION:
- Hold/suspend the domain
en-trezor.org at the registry level (Public Interest Registry).
- Terminate Cloudflare proxying and DNS resolution for
en-trezor.org.
- Submit this domain to global threat blacklists.
Regards,
Security Researcher

Dear Abuse & Security Team,
I am writing to submit an urgent phishing report regarding an active malicious domain registered under the .ORG TLD targeting Trezor Hardware Wallet users.
INFRASTRUCTURE DETAILS:
THREAT DETAILS:
The domain
en-trezor.orgemploys brand spoofing and prefix typosquatting ("en-trezor") to impersonate the official Trezor interface. The site is engineered to deceive victims into entering their 12/24-word Secret Recovery Seed Phrases or connecting wallets to drain cryptocurrency assets.VIOLATIONS:
REQUESTED ACTION:
en-trezor.orgat the registry level (Public Interest Registry).en-trezor.org.Regards,
Security Researcher