← Tronify.rent1 decision on this page
Audit log
Every state-changing event for Tronify.rent: moderation decisions on community submissions, plus corrections and updates from the news pipeline. URL-based decisions are designed to carry three independent witnesses — the original source, an Internet Archive snapshot, and a Solana memo signed by our publicly-disclosed publisher key. Archive coverage is still being backfilled, so each decision below reports its own snapshot status rather than assuming one exists.
- #1publishby system:backfill2026-10-08 17:05:17ZScore: ? → ? (no score change)anchorfailed
- chain
- ●—
- hash
CbTDCFmCRB4z…bAFwaumMsha256 → base58
verifying row…canonical bytes (17338 B) ▸
{"actor":"system:backfill","investigation_id":"0c87a076-58e5-4d0b-b99f-b131643c86fa","kind":"publish","page_slug":"tronify-rent","published_at":"2026-10-08T17:05:17.583Z","sequence_num":1,"snapshot":{"content_type":"investigation","entity_name":"Tronify.rent","sections":[{"content":"Tronify.rent presents itself as a noncustodial TRON energy rental platform, mimicking the legitimate service Tronify (tronify.io), which provides TRON network resource management and is integrated with Trust Wallet. The fraudulent site uses the .rent top-level domain rather than misspelling the brand name, a technique that exploits brand recognition without triggering simple typosquatting filters. The site claimed to be operated by 'Tronify Energy Solutions LLC' with a Florida address, asserted SOC 2 Type II compliance, and displayed a 'currently in beta testing' notice with a 'Service Launching Q1 2025' statement alongside a 2024 copyright notice — none of which have been independently verified. Trust Wallet's official Tronify integration links to tronify.io, not tronify.rent. The domain was registered on November 25, 2025, via TLD Registrar Solutions Ltd (GB), with registrant details hidden behind a privacy service.","heading":"Overview and Brand Impersonation","severity":"critical","sources":[{"credibility":2,"name":"Google's Gemini-Powered AI Search Called Tronify.rent 'Official'. Users Lost $69,651 — The Crypto Times","type":"news_article","url":"https://www.cryptotimes.io/2026/10/05/google-ai-searchs-official-tronify-rent-label-raises-questions-after-69651-losses/"},{"credibility":2,"name":"Google Gemini cited in $69K crypto scam report — crypto.news","type":"news_article","url":"https://crypto.news/google-gemini-cited-in-69k-crypto-scam-report/"},{"credibility":2,"name":"Tronify official X account (tronify.io)","type":"official","url":"https://x.com/Tronify_io"}]},{"content":"When a user connects a wallet to tronify.rent, the site injects a malicious JavaScript file, greenbid.js (150,274 bytes; SHA-256: 0f6d64472d6369a098f403db117b1285e79b0fdac79caaa639fc0e50e5bf4416), loaded from the external domain lending.fhogu.pw. The payload issues TRC-20 increaseApproval() calls requesting unlimited token amounts, then transfers the full approved balance to attacker-controlled addresses. Wallet notifications documented in the independent threat intelligence report by researcher Krishanu show: an unlimited USDT approval granted to address TV6n8cCLmX5mRCMMNvcE1K1i87Yo9Ys5rv, receipt of 15 TRX from that same address (a 'priming' technique used when victims lack sufficient TRX for gas fees), followed by a transfer of 1,419.699184 USDT to sweep address TLv3iSnZxWghEmadLDzuAK2p5GkAwg7tpJ. The payload communicates with 12 command-and-control endpoints, including a client telemetry endpoint at /tron/client-log. Targeted wallet providers include Trust Wallet, TronLink, OKX Wallet, TokenPocket, Bitget, SafePal, and WalletConnect. The researcher identified at least 25 distinct victim wallets and $32,500+ in confirmed on-chain USDT theft within a 30-day window as of September 20, 2026, with theft activity described as ongoing at that date.","heading":"Scam Mechanism and Technical Indicators","severity":"critical","sources":[{"credibility":2,"name":"tronify.rent Wallet Drainer — Independent Threat Intel Report by Krishanu","type":"research","url":"https://krishanu1.retailflow.co.in/"},{"credibility":2,"name":"Google Gemini cited in $69K crypto scam report — crypto.news","type":"news_article","url":"https://crypto.news/google-gemini-cited-in-69k-crypto-scam-report/"}]},{"content":"JP, founder of IOC Investigations (X: @rugpullfinder), published findings on October 4, 2026, alleging approximately 80 victims lost a combined $69,651 during September 2026. JP identified 12 TRON addresses allegedly associated with the operation but did not publish a transaction-by-transaction breakdown, and The Crypto Times noted that independent verification of the full loss total had not been completed at time of publication. A Reddit user separately reported in June 2026 losing 2,590 USDT after connecting a Trust Wallet to the site and stated they had filed a complaint with the FBI's Internet Crime Complaint Center. The independent on-chain analysis by Krishanu identified at least 25 distinct victim wallets and confirmed $32,500+ in USDT theft in a 30-day window, providing partial corroboration for the broader loss figures. The discrepancy between the confirmed on-chain figure and the total alleged loss figure has not been publicly resolved.","heading":"Reported Victim Losses","severity":"critical","sources":[{"credibility":3,"name":"JP (@rugpullfinder) on X","type":"social_media","url":"https://x.com/rugpullfinder"},{"credibility":2,"name":"Google's Gemini-Powered AI Search Called Tronify.rent 'Official'. Users Lost $69,651 — The Crypto Times","type":"news_article","url":"https://www.cryptotimes.io/2026/10/05/google-ai-searchs-official-tronify-rent-label-raises-questions-after-69651-losses/"},{"credibility":2,"name":"tronify.rent Wallet Drainer — Independent Threat Intel Report by Krishanu","type":"research","url":"https://krishanu1.retailflow.co.in/"},{"credibility":2,"name":"Gemini Cited in Tronify.rent Crypto Scam Investigation — Analytics Insight","type":"news_article","url":"https://www.analyticsinsight.net/cryptocurrency-analytics-insight/gemini-cited-in-tronifyrent-crypto-scam-investigation"}]},{"content":"Investigator JP alleged that at least one victim queried Google's Gemini-powered AI search assistant before connecting their wallet and received a response stating: 'The official, correct web domain is tronify.rent.' The response reportedly cited Trust Wallet's Tronify integration as supporting evidence, despite Trust Wallet linking to tronify.io rather than tronify.rent. JP has linked this alleged AI validation to victim losses, arguing it provided a false legitimacy signal that increased the likelihood of victims proceeding with the wallet connection. Google has not publicly confirmed this interaction, has not disclosed the specific prompt used, and has not explained how Gemini evaluated the website. Google's own documentation acknowledges that Gemini can provide inaccurate information. The victim's exact prompt and Gemini's full verbatim response have not been independently published. This allegation is attributed to JP's investigation report and has not been adjudicated or confirmed by any regulatory body or court.","heading":"Google Gemini AI Validation Allegation","severity":"high","sources":[{"credibility":2,"name":"Google's Gemini-Powered AI Search Called Tronify.rent 'Official'. Users Lost $69,651 — The Crypto Times","type":"news_article","url":"https://www.cryptotimes.io/2026/10/05/google-ai-searchs-official-tronify-rent-label-raises-questions-after-69651-losses/"},{"credibility":2,"name":"Tronify Scam Report Cites Gemini Claim — CoinInsider","type":"news_article","url":"https://www.coininsider.org/news/google-gemini-cited-in-69k-tronify-scam-report/"},{"credibility":2,"name":"Google Gemini cited in $69K crypto scam report — crypto.news","type":"news_article","url":"https://crypto.news/google-gemini-cited-in-69k-crypto-scam-report/"}]},{"content":"PhishDestroy first observed and flagged tronify.rent on February 26, 2026 — within five days of the domain's registration on February 21, 2026 — assigning it a threat score of 90/100 and identifying crypto-scam and brand-impersonation signals. In April 2026, two formal abuse reports were filed against the domain: one sent to the registrar TLD Registrar Solutions Ltd and a second escalation copied to ICANN Compliance. PhishDestroy notes that filing an abuse report does not confirm the registrar received, investigated, or acted on it. The domain remained accessible and active through at least October 8, 2026, the date of PhishDestroy's last recorded check, at which point it returned HTTP 200 and was hosted on IP 104.21.2.88 (Cloudflare CDN). VirusTotal detection on the stored snapshot showed 1 out of 91 engines flagging the domain, and Google Safe Browsing had not stored a flag as of that date. An associated suspected fraudulent domain, tron.store, was identified with similar infrastructure.","heading":"Prior Security Warnings and Failure to Take Down","severity":"high","sources":[{"credibility":2,"name":"PhishDestroy — tronify.rent threat intelligence record","type":"research","url":"https://phishdestroy.io/domain/tronify.rent/"},{"credibility":2,"name":"Google Gemini cited in $69K crypto scam report — crypto.news","type":"news_article","url":"https://crypto.news/google-gemini-cited-in-69k-crypto-scam-report/"},{"credibility":2,"name":"Gemini Cited in Tronify.rent Crypto Scam Investigation — Analytics Insight","type":"news_article","url":"https://www.analyticsinsight.net/cryptocurrency-analytics-insight/gemini-cited-in-tronifyrent-crypto-scam-investigation"}]},{"content":"The domain tronify.rent was registered November 25, 2025 (with PhishDestroy recording a separate registration observation date of February 21, 2026, suggesting a possible re-registration or conflicting WHOIS records) via TLD Registrar Solutions Ltd (GB) with registrant details obscured by a privacy service. The site is served through Cloudflare CDN; the origin server location has not been confirmed. Investigator JP noted the DDoS protection provider used is based in Russia. The malicious greenbid.js payload is hosted on the secondary domain lending.fhogu.pw, indicating a split-infrastructure design intended to survive partial takedowns. No law enforcement attribution, criminal charges, or regulatory action against the operators of tronify.rent had been publicly announced as of October 8, 2026.","heading":"Infrastructure and Attribution","severity":"high","sources":[{"credibility":2,"name":"tronify.rent Wallet Drainer — Independent Threat Intel Report by Krishanu","type":"research","url":"https://krishanu1.retailflow.co.in/"},{"credibility":2,"name":"Google's Gemini-Powered AI Search Called Tronify.rent 'Official'. Users Lost $69,651 — The Crypto Times","type":"news_article","url":"https://www.cryptotimes.io/2026/10/05/google-ai-searchs-official-tronify-rent-label-raises-questions-after-69651-losses/"},{"credibility":2,"name":"PhishDestroy — tronify.rent threat intelligence record","type":"research","url":"https://phishdestroy.io/domain/tronify.rent/"}]},{"content":"The following indicators of compromise (IOCs) have been published by independent researchers. Users who have connected wallets to tronify.rent should check token approvals immediately and revoke any unlimited allowances. Malicious domains: tronify.rent and lending.fhogu.pw. Malicious payload: greenbid.js (SHA-256: 0f6d64472d6369a098f403db117b1285e79b0fdac79caaa639fc0e50e5bf4416, 150,274 bytes). Attacker-controlled TRON addresses: token spender TV6n8cCLmX5mRCMMNvcE1K1i87Yo9Ys5rv; sweep destination TLv3iSnZxWghEmadLDzuAK2p5GkAwg7tpJ. Hosting IP (Cloudflare fronted): 104.21.2.88. JP's investigation additionally identified 12 TRON addresses associated with the broader operation; the full list was published in his October 4, 2026 report on X.","heading":"Indicators of Compromise","severity":"critical","sources":[{"credibility":2,"name":"tronify.rent Wallet Drainer — Independent Threat Intel Report by Krishanu","type":"research","url":"https://krishanu1.retailflow.co.in/"},{"credibility":3,"name":"JP (@rugpullfinder) on X","type":"social_media","url":"https://x.com/rugpullfinder"}]}],"sources_used":[{"credibility":2,"name":"Google's Gemini-Powered AI Search Called Tronify.rent 'Official'. Users Lost $69,651 — The Crypto Times","type":"news_article","url":"https://www.cryptotimes.io/2026/10/05/google-ai-searchs-official-tronify-rent-label-raises-questions-after-69651-losses/"},{"credibility":2,"name":"Google Gemini cited in $69K crypto scam report — crypto.news","type":"news_article","url":"https://crypto.news/google-gemini-cited-in-69k-crypto-scam-report/"},{"credibility":2,"name":"Gemini Cited in Tronify.rent Crypto Scam Investigation — Analytics Insight","type":"news_article","url":"https://www.analyticsinsight.net/cryptocurrency-analytics-insight/gemini-cited-in-tronifyrent-crypto-scam-investigation"},{"credibility":2,"name":"Tronify Scam Report Cites Gemini Claim — CoinInsider","type":"news_article","url":"https://www.coininsider.org/news/google-gemini-cited-in-69k-tronify-scam-report/"},{"credibility":2,"name":"Google Gemini Blamed in $69K Crypto Scam — Bitbase","type":"news_article","url":"https://www.bitbase.com/news/google-gemini-cited-in-69k-crypto-scam-report"},{"credibility":2,"name":"tronify.rent Wallet Drainer — Independent Threat Intel Report by Krishanu","type":"research","url":"https://krishanu1.retailflow.co.in/"},{"credibility":2,"name":"PhishDestroy — tronify.rent threat intelligence record","type":"research","url":"https://phishdestroy.io/domain/tronify.rent/"},{"credibility":3,"name":"JP (@rugpullfinder) on X","type":"social_media","url":"https://x.com/rugpullfinder"},{"credibility":2,"name":"Tronify official X account (tronify.io)","type":"official","url":"https://x.com/Tronify_io"}],"summary":"Tronify.rent is a fraudulent website that impersonates Tronify, a legitimate TRON energy-rental service (tronify.io), by exploiting the .rent top-level domain. The site injects a malicious JavaScript payload upon wallet connection that calls TRC-20 increaseApproval() for unlimited token amounts and sweeps victim balances to attacker-controlled addresses. Approximately 80 victims reportedly lost a combined $69,651 during September 2026, and the domain remained live despite abuse reports filed as early as April 2026. The case drew additional attention after an investigator alleged that Google's Gemini-powered AI search assistant endorsed tronify.rent as Tronify's official domain in response to a victim query — a claim Google has not confirmed.","timeline":[{"date":"2025-11-25","event":"Domain tronify.rent registered via TLD Registrar Solutions Ltd with privacy-protected registrant details.","source":"crypto.news / PhishDestroy WHOIS data","source_url":"https://crypto.news/google-gemini-cited-in-69k-crypto-scam-report/"},{"date":"2026-02-21","event":"PhishDestroy records domain registration observation for tronify.rent (alternate date per PhishDestroy WHOIS snapshot).","source":"PhishDestroy — tronify.rent threat intelligence record","source_url":"https://phishdestroy.io/domain/tronify.rent/"},{"date":"2026-02-26","event":"PhishDestroy first flags tronify.rent, assigning a threat score of 90/100 with crypto-scam and brand-impersonation classifications.","source":"PhishDestroy — tronify.rent threat intelligence record","source_url":"https://phishdestroy.io/domain/tronify.rent/"},{"date":"2026-04-01","event":"Two abuse reports filed against tronify.rent: one to registrar TLD Registrar Solutions Ltd, one to ICANN Compliance. Domain remains live after both reports.","source":"Google Gemini cited in $69K crypto scam report — crypto.news","source_url":"https://crypto.news/google-gemini-cited-in-69k-crypto-scam-report/"},{"date":"2026-06-01","event":"Reddit user reports losing 2,590 USDT after connecting a Trust Wallet to tronify.rent; files complaint with FBI Internet Crime Complaint Center.","source":"Google Gemini cited in $69K crypto scam report — crypto.news","source_url":"https://crypto.news/google-gemini-cited-in-69k-crypto-scam-report/"},{"date":"2026-09-01","event":"Active theft campaign during September 2026 — approximately 80 victims allegedly lose a combined $69,651 according to investigator JP.","source":"The Crypto Times — Google AI search official label","source_url":"https://www.cryptotimes.io/2026/10/05/google-ai-searchs-official-tronify-rent-label-raises-questions-after-69651-losses/"},{"date":"2026-09-20","event":"Independent researcher Krishanu documents active theft, identifying at least 25 victim wallets and $32,500+ in confirmed on-chain USDT theft within a 30-day window.","source":"tronify.rent Wallet Drainer — Independent Threat Intel Report by Krishanu","source_url":"https://krishanu1.retailflow.co.in/"},{"date":"2026-10-04","event":"JP (IOC Investigations, @rugpullfinder) publishes investigation on X, identifying 12 TRON addresses, alleging $69,651 in losses across ~80 victims, and alleging a victim received false validation from Google Gemini.","source":"The Crypto Times — Google AI search official label","source_url":"https://www.cryptotimes.io/2026/10/05/google-ai-searchs-official-tronify-rent-label-raises-questions-after-69651-losses/"},{"date":"2026-10-05","event":"The Crypto Times, crypto.news, Analytics Insight, CoinInsider, and others publish coverage of the investigation and the Google Gemini allegation.","source":"Google's Gemini-Powered AI Search Called Tronify.rent 'Official' — The Crypto Times","source_url":"https://www.cryptotimes.io/2026/10/05/google-ai-searchs-official-tronify-rent-label-raises-questions-after-69651-losses/"},{"date":"2026-10-08","event":"PhishDestroy last-check confirms tronify.rent returns HTTP 200 and remains live. No law enforcement action or domain takedown has been announced.","source":"PhishDestroy — tronify.rent threat intelligence record","source_url":"https://phishdestroy.io/domain/tronify.rent/"}]},"v":1}Verify offline (run on your own machine)python -m src.verify_decision 30ecdbb3-ba8e-48fd-ae2e-7f0dc277bab5
How verification works. The “Row integrity” check above is computed in your browser — your machine recomputes the SHA-256 of the canonical bytes and compares against the stored hash. No avoid.net server can fake that check. The “full verify” link goes one level deeper: your browser fetches the on-chain transaction from a Solana RPC node and confirms the same hash is in the memo. If you don’t want to trust either avoid.net or the public RPC, run the CLI verifier on your own machine —
python -m src.verify_decision <event_id>.