Google Gemini Blamed in $69K Crypto Scam

TRX
USDT
AI MisinformationGoogle GeminiWallet DrainCrypto ScamphishingTRON
2 hours agoSource: crypto.news
Google Gemini Blamed in $69K Crypto Scam

Google Gemini has been cited in a crypto investigator’s report alleging that Tronify.rent took $69,651 from roughly 80 victims during September after at least one user said the AI service had described the website as safe.

Summary

  • About 80 users reportedly lost $69,651 through Tronify.rent during September, according to investigator JP online.
  • JP alleges Google Gemini recommended Tronify.rent and even told one victim the website appeared safe.
  • Independent threat researchers had already flagged Tronify.rent months earlier for phishing and brand impersonation risks.
  • PhishDestroy recorded abuse reports against Tronify.rent in April while the website remained publicly reachable afterward.
  • Google warns Gemini can make mistakes and advises users to verify responses independently before acting.

JP, founder of IOC Investigations, said the TRON-focused website received funds from victims through several addresses and claimed a victim had asked Gemini whether the service was legitimate before interacting with it. His Oct. 4 post listed 12 TRON addresses that he associated with the operation.

The $69,651 figure and roughly 80-victim count come from JP’s investigation. No independent blockchain-forensics report reviewed for this article has separately reproduced the full loss total across the listed addresses.

Tronify scam claims center on wallet connections

Tronify.rent presents itself as a TRON energy rental service promising to cut transaction costs for users moving assets on the network.

The website currently claims it is a noncustodial service and tells visitors they retain control of their assets. Its interface includes a wallet connection feature and promotes energy delegation for TRC-20 transactions.

Victim reports tell a different story. A Reddit user reported in June that funds were drained after connecting a Trust Wallet to Tronify.rent, claiming a loss of 2,590 USDT. The account said it later filed a complaint with the FBI’s Internet Crime Complaint Center. Reddit posts are user-generated reports and do not independently establish criminal liability.

JP’s October post said approximately 80 people were affected during the previous month. He published the addresses he linked to the activity but did not provide a public transaction-by-transaction breakdown showing how the $69,651 total was calculated.

The investigator separately flagged tron.store as another suspected scam site. Independent threat research provides some support for concern around related infrastructure: PhishDestroy previously recorded a domain using the page title “tron.store – Rent Energy” and classified the associated site as high risk for crypto phishing and brand impersonation.

Independent security checks flagged Tronify months earlier

Security warnings about Tronify.rent predate the latest victim report. PhishDestroy flagged the domain in February and later assigned it a critical threat rating of 90/100. Its stored intelligence identified crypto-scam and brand-impersonation signals and recorded threat-feed detections tied to the site.

The security service recorded two abuse reports in April, including one sent to the domain registrar and another escalation that copied ICANN Compliance. Its monitoring later found the domain remained reachable. PhishDestroy cautions that an outgoing abuse report does not prove a registrar received, investigated or acted on the complaint.

WHOIS records show that Tronify.rent was registered on Nov. 25, 2025, with registrant details hidden through a privacy service. The registration currently lists TLD Registrar Solutions as the registrar.

The website itself claims to operate as “Tronify Energy Solutions LLC,” lists a Florida address and says its infrastructure is SOC 2 Type II compliant. No independent audit or regulatory document confirming those website claims was identified in the sources reviewed for this report.

JP claimed the operation used DDoS protection linked to Russia. Independent network data reviewed here does not confirm that point. PhishDestroy’s stored observations identified Cloudflare as the site’s edge network and noted that the origin server was hidden behind the CDN, meaning the origin’s geographic location could not be established from that edge IP.

Gemini recommendation claim remains unconfirmed by Google

The most unusual part of the report concerns Google Gemini. JP said a victim reported asking Gemini whether Tronify.rent was safe and receiving a response that appeared to endorse the website. The investigator described the reported answer as Gemini confirming the site was safe.

No public statement from Google reviewed for this article has confirmed that interaction, identified the prompt used or explained how Gemini may have evaluated the website.

Google nevertheless explicitly warns that generative AI can produce inaccurate information and tells users to check claims presented as facts using other sources.

Its general Gemini guidance similarly says Gemini Apps can make mistakes and advises users to double-check responses before relying on them.

Google’s AI security documentation goes further when web content is involved. The company explains that malicious webpages can contain material intended to influence generative AI systems through prompt-injection techniques. Google says Gemini uses safeguards to detect suspicious material, though users can still report responses they believe are unsafe or inaccurate.

Google has separately warned about cryptocurrency fraud using artificial intelligence. In a June fraud advisory, the company reported scams involving fake crypto investments, fraudulent mining software and deceptive AI bot tutorials designed to lead users toward malicious code or wallet-draining activity.

AI is becoming part of crypto scam tactics

The Tronify allegation comes as security researchers continue documenting scams that use AI branding or trusted technology platforms to make malicious offers appear safer.

In September, TRM Labs documented fake AI trading bot tutorials that stole $517,000 from 224 victims. The campaign used videos presenting automated crypto-arbitrage tools while malicious infrastructure caused users to deploy contracts that sent funds to attacker-controlled addresses.

Another campaign used Google-style phishing emails targeting crypto traders, relying on legitimate-looking Google account notifications to make malicious links appear more trustworthy.

The mechanism described in the Tronify complaints resembles the risks covered in crypto.news’ guide to wallet drainers and approval phishing, where users authorize transactions or permissions that later allow attackers to move tokens from their wallets.

Independent threat data on Tronify.rent shows why an AI-generated safety answer, if the victim report is accurate, would have conflicted with existing warning signs. By April, the domain had already been reported to its registrar by a security service, while later scans continued to classify it as high risk.

Google’s current Gemini safety guidance says users should evaluate AI-generated responses critically and verify claims before acting, especially where inaccurate information could create financial or security risks.