Invest1 publisher2 min readPublished
Gemini allegedly vouched for Tronify.rent months after a threat feed flagged it as phishing
Investigator JP says Tronify.rent took $69,651 from about 80 crypto users in September and that Google Gemini told one victim the site appeared safe. PhishDestroy had already scored the domain a critical 90/100 threat before that money went to the site.
The Investor · Invest desk
Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction

What happened
- Tronify.rent presents itself as a noncustodial TRON energy rental service, and its interface asks visitors to connect a wallet.
- PhishDestroy recorded two abuse reports in April, one to the registrar and one copying ICANN Compliance, and the domain stayed reachable afterward.
- A Reddit user said in June that connecting a Trust Wallet to the site drained 2,590 USDT and that a complaint went to the FBI's IC3.
- JP's Oct. 4 post listed 12 TRON addresses he tied to the operation but gave no transaction-level breakdown of his loss total.
- Google has not confirmed the Gemini account, and its standing guidance is that Gemini can make mistakes and answers should be verified.
Compiled by The InvestorSomething wrong?How this is made
Why it matters
- exposure Wallets and exchanges whose users check sites through an AI assistant are exposed whenever the assistant lags behind threat feeds, and in this case the feed had been warning for about seven months.
- decision Abuse reports left the site reachable, so the operators of wallets and assistants have to decide whether to block on third-party threat ratings instead of waiting for a registrar.
- contradiction Network data did not confirm JP's claim of Russia-linked DDoS protection, so his Gemini account should be weighed as one investigator's unverified report.
- constraint Until someone reconciles the 12 addresses to $69,651, any sizing of losses from AI-endorsed phishing sites rests on a single investigator's count.
Divide JP's $69,651 by his roughly 80 victims and the average loss comes to about $871 a person [1]. That total is his own count. He has not published how the 12 addresses add up to it [3], and crypto.news found no independent forensic report that reproduces it [4]. The separately reported Reddit loss came in June, before the September window he counted [3]. By that one user's account, the site was draining wallets before the month in his total [6].
The dates say more than the per-victim figure. The domain was registered on Nov. 25, 2025, with the owner hidden behind a privacy service [9]. PhishDestroy flagged it in February and later scored it a critical 90 out of 100 [7]. After the April abuse reports, PhishDestroy found the domain still reachable [8]. It also cautions that sending a report does not prove a registrar received it, investigated it or acted on it [10]. About seven months separate the first flag from the September losses [2].
The site claims to be "Tronify Energy Solutions LLC" at a Florida address, with SOC 2 Type II compliance. In the sources crypto.news reviewed, no audit or regulatory document backed any of that [14]. The Gemini detail is secondhand. A victim told JP that Gemini, asked whether the service was legitimate, gave an answer that appeared to endorse it, and JP made that public [2]. It is one account among roughly 80 victims [1].
If Google or the victim produces the exchange, the failure is specific: an assistant answered a direct legitimacy question about a domain a threat feed had rated critical. A user-protection team could test for that by putting domains from its own blocklist to the assistants its customers use. If the exchange never surfaces, the Gemini line stays an anecdote attached to a domain that kept running after abuse reports [8]. A forensic count of the 12 addresses could also move the $69,651 in either direction [3].
I think the compliance case holds in both versions. The cash went to a domain a security feed had already marked [7], and that warning did not reach users at the moment they connected their wallets. The counter-thesis is that the chatbot is a headline hung on an ordinary registrar failure, and for the Gemini part specifically the current evidence supports it. The view is wrong if Gemini turns out to have warned about the site and the victim connected anyway.
What to watch
- Whether Google responds to JP's account, or the victim publishes the Gemini exchange itself.
- An independent forensic tally of the 12 TRON addresses measured against JP's $69,651 total.
- Whether TLD Registrar Solutions suspends Tronify.rent or the site keeps accepting wallet connections.