A Trezor phishing scam promoted through a Google-sponsored ad has reportedly drained one user’s life savings, the victim says. Elsewhere, BTCPay Server shipped an emergency patch for a critical flaw already under active exploitation.
The two incidents landed within roughly 24 hours of each other. Neither touched the Bitcoin (BTC) protocol itself, yet both put user funds at direct risk.
Google Ad Funnels Victims to Trezor Phishing Site
The victim, posting on X (Twitter) under the name David, blamed a sponsored search ad on Thursday. Based on the report, the ad placed a counterfeit Trezor page, hosted on Google Sites, above the wallet maker’s real website.
Anyone who typed a recovery seed into the page handed attackers full control of their wallet.
On-chain data shows the wallet flagged in the report received 24.04 BTC across 80 transactions. That haul equals roughly $1.6 million at Bitcoin’s current price near $65,172. However, nearly all of it has moved on, leaving about 0.04 BTC behind.
Trezor said it escalated the case internally and reported the page for takedown.
“For everyone reading: always verify that you’re using the official Trezor website and never enter your wallet backup into a website or form,” the team urged.
The hardware itself was never breached. The attack worked because the seed left the device. The playbook echoes a fake Uniswap phishing site that drained $400,000 from wallets in May.
BTCPay Server Rushes Out Patch for Exploited Flaw
Meanwhile, BTCPay Server, open-source software that lets merchants accept bitcoin payments directly, issued its own warning on Friday.
Follow us on X to get the latest news as it happens
The team told operators to update to version 2.4.2 immediately or power servers down until they can.
“This release contains fix of a critical vulnerability that is being actively exploited. You need to update as fast as you can,” the project’s release notes state.
The Bitcoin Red Team, a volunteer security research group, reported the flaw to developers.
However, patching alone does not end the cleanup. Operators must also refresh macaroons, the access credentials Lightning nodes rely on, plus auth strings for other backends.
Anyone who generated a hot wallet inside BTCPay should move those funds and recreate it. Integrators should also update NBXplorer, a companion indexing tool, to version 2.6.10.
Why Both Incidents Matter for Bitcoin Self-Custody
One attack exploited trust in search ads. In contrast, the other exploited code running on merchant servers. Both sidestepped Bitcoin’s security model and hit the software and habits around it instead.
Phishing remains the costliest threat in crypto. January’s crypto theft losses reached about $400.3 million, and one phishing attack drove over 70% of that figure.
Google has yet to explain how the fraudulent ad cleared review. How fast the page comes down, and how many BTCPay operators patch in time, will shape the damage.
The post Trezor Phishing Ad and BTCPay Exploit Hit Bitcoin Users: Are Funds Safe? appeared first on BeInCrypto.
Security,Bitcoin (BTC) News,Crypto Crime News,Editor’s Pick#Trezor #Phishing #BTCPay #Exploit #Hit #Bitcoin #Users #Funds #Safe1786126121

