News · DiggingBeagle record

Google AI Mode reportedly called a flagged Tronify domain official before a wallet decision

The domain was already associated with security warnings and an earlier alleged loss when Google AI Mode reportedly identified it as Tronify's official site. The important failure is narrower than 'AI caused the scam': legitimate evidence about a company was apparently converted into trust for an unverified endpoint just before a wallet authorization decision.

The report

A user asked Google Search AI Mode two questions that sound simple but are not equivalent: which Tronify website is official, and whether it is safe to connect a wallet. According to The Crypto Times, AI Mode identified tronify.rent as the official domain and supported the answer with a real fact, Trust Wallet had integrated a TRON energy provider called Tronify.

The cited fact did not authenticate the domain. Trust Wallet's own announcement confirms the Tronify integration but does not identify tronify.rent. The Crypto Times reports that an earlier Trust Wallet page instead linked the provider at tronify.io.

That distinction matters because tronify.rent was not a new domain appearing only after the AI answer. PhishDestroy's threat record dates its first detection to February 26, 2026. On June 3, months before the reported AI Mode interaction, a Reddit user alleged losing 2,590 USDT after connecting Trust Wallet to the site's dApp.

The scam allegation therefore predates Google AI Mode. The AI-security question is what happened later, when an AI-generated answer reportedly transferred legitimate Tronify reputation to the disputed endpoint.

What the evidence actually establishes

Evidence What it supports What it does not establish
Trust Wallet's Tronify announcement Tronify was a real energy provider integrated into Trust Wallet That tronify.rent belonged to that provider
PhishDestroy's domain record Warning evidence concerning tronify.rent existed before September That every later loss allegation is verified
June Reddit report One user publicly alleged a 2,590 USDT loss after using the site A connection to Google AI Mode
Crypto Times report A screenshot reportedly shows AI Mode calling tronify.rent official How the domain entered the answer or whether Google independently confirmed the incident
Wallet screenshot described by The Crypto Times An unlimited USDT approval and a later 1,419.699184 USDT transfer are shown in the reported evidence That the wallet belonged to the same person shown asking AI Mode for advice

JP also alleged $69,651 in September losses across roughly 80 people. The Crypto Times says it did not independently verify that aggregate amount or victim count, so those figures remain an allegation rather than a confirmed loss metric.

The failure happened between a true fact and a false conclusion

The useful distinction is endpoint identity binding. An assistant can correctly identify a real company, product or partnership and still fail when it maps that identity onto a domain, contract address, package or login endpoint.

In this case, the proposition Trust Wallet works with Tronify could be true while the proposition tronify.rent is Tronify's official domain is false or unsupported. Evidence for the first proposition does not prove the second.

Google's own AI Mode documentation says the system can misinterpret web content or miss context and advises users to check important information in more than one place. That is a useful product-level warning, but it does not resolve the specific error. A confident endpoint recommendation can already have shaped the user's decision before a general caution is applied.

The wallet signature is a second security boundary

The reported AI answer did not itself transfer tokens. A human remained in the authorization path.

The Crypto Times describes a second screenshot showing an unlimited USDT approval followed one minute later by a 1,419.699184 USDT transfer to addresses on JP's list. An unlimited allowance gives the approved spender continuing authority over the token balance. That is a separate security decision from deciding whether the website looks legitimate.

This produces two independent checks:

  1. Endpoint check: does authoritative evidence bind the exact domain or contract to the legitimate entity?
  2. Authority check: what does the proposed wallet signature allow the spender to do?

Passing the first check does not make an unlimited approval safe. Failing the first check should not be repaired by a warning displayed only after the user has already been told the endpoint is official.

This is not the same mechanism as an autonomous wallet agent

The distinction is visible when this incident is compared with the Bankr case and Zscaler's staged payment demonstration.

In those records, hostile or untrusted text entered an AI-agent workflow that possessed action authority. The security question was whether model-controlled reasoning could reach a signer or payment tool.

No equivalent chain is established here. There is no public evidence that tronify.rent injected instructions into AI Mode, no evidence that AI Mode controlled the wallet, and no evidence that an AI agent signed the transaction. The model's reported role was advisory: it appears to have supplied a trust judgment immediately upstream of a human authorization decision.

That is still an AI-security boundary. Recommendation becomes consequential when a person uses the model as an identity oracle for an endpoint that can request irreversible permissions.

What remains unproven

The complete original prompt and AI Mode transcript are not public in the reviewed evidence, and the exact model or model-selection state is unknown. No reviewed source establishes whether tronify.rent entered the answer through ordinary retrieval, search ranking, adversarial manipulation or another mechanism.

The public record also does not prove that the AI screenshot and wallet screenshot belong to the same victim. The June Reddit report is a separate allegation, while JP's $69,651 total and approximately 80-victim estimate have not been independently reconstructed from the underlying addresses.

The defensible conclusion is therefore narrower than 'Google AI stole crypto.' The documented case shows a reported AI trust failure around a domain that already carried warning signals. The security lesson is that a correct fact about an entity cannot substitute for evidence about the exact endpoint, and an endpoint judgment cannot substitute for inspecting the authority a wallet is about to grant.

Research behind this

Cite this record

DiggingBeagle. “Google AI Mode reportedly called a flagged Tronify domain official before a wallet decision.” https://diggingbeagle.com/news/google-ai-mode-tronify-rent-official-domain-wallet-risk/

Citation guidance