Reports about Tronify.rent describe an alleged TRON energy-rental scam, but the central figures and details come from investigator JP’s account. JP says about 80 people lost $69,651 in September; one person reportedly told investigators that Google’s Gemini had described the site as safe. The available material does not independently verify the total, the victim’s account of the Gemini exchange, or a direct link between that answer and the reported losses.
14
19
What the reports allege
Tronify.rent presented itself as a noncustodial service for renting TRON energy to reduce transaction costs and asked users to connect a wallet. Some users reportedly lost funds after interacting with the site. But the reports available here do not establish what each person did after connecting, what transaction or permission they approved, or precisely how the funds moved. So the reported sequence does not prove that connecting a wallet, by itself, caused funds to be taken.
8
13
JP, the founder of IOC Investigations, reportedly identified 12 TRON addresses associated with the suspected operation. Those addresses are investigative leads; their attribution and connection to the alleged losses have not been independently established in the material reviewed here.
14
8
What is reported about Gemini—and the site’s claims
The Gemini account is also based on a victim’s reported recollection, not a publicly verified transcript. A separate report says the alleged answer described Tronify.rent as an official domain and referred to a Trust Wallet integration; that report says the integration was associated with the different domain tronify.io. The available sources do not confirm the original exchange or establish that Gemini caused anyone to use the site.
6
19
There was also a warning before the reported September losses: coverage says PhishDestroy had flagged Tronify.rent in February 2026, reportedly giving it a 90-out-of-100 threat score. A PhishDestroy listing categorizes the domain as cryptocurrency-related and identifies Bitget brand impersonation. A warning is relevant context, but it does not by itself verify who operated the domain or prove every alleged theft.
1
16
What remains unverified
The reports support describing the losses as allegations attributed to JP and victims—not as a confirmed, independently audited total. The available material does not independently confirm the victim count, the $69,651 figure, the ownership of Tronify.rent, the attribution of the 12 addresses, the exact Gemini response, or whether any funds were recovered.
14
19
Don’t use an AI answer as a security check
Google’s own help materials say Gemini can make mistakes, and Google also describes prompt injection as a way malicious content can try to elicit unintended responses from generative AI tools. Those general warnings do not show that prompt injection—or any other manipulation—occurred in this case. They do reinforce a practical limit: a chatbot’s confident response cannot verify a site’s ownership, wallet permissions or safety.
21
32
Before using a crypto service, verify the domain through independent channels and check available threat warnings. Treat wallet connection and any subsequent transaction or signature request as separate moments to assess: review what the wallet is asking you to approve, and stop if you cannot understand it. A security guide from GMGN likewise recommends skepticism toward platforms and wallet authorization signatures.
20