
A Google Ad Funnels Victims to Trezor Phishing Site within 24 hours of the BTCPay Server exploit. According to reports, anyone who typed a recovery seed into the fraudulent page handed attackers full control of their wallet. On-chain data shows the compromised wallet received 24.04 BTC across 80 transactions, equivalent to approximately $1.6 million at Bitcoin's current price near $65,172. However, nearly all of the stolen funds have moved on, leaving only about 0.04 BTC behind. Trezor has escalated the case internally and reported the page for takedown, urging users to always verify official Trezor websites and never enter wallet backup information into websites or forms. The hardware itself was never breached - the attack worked because the seed left the device, similar to a fake Uniswap phishing site that drained $400,000 from wallets in May.
BTCPay Server, open-source software for merchants accepting Bitcoin payments directly, issued an urgent warning on Friday regarding a critical vulnerability. As reported, the team advised operators to update to version 2.4.2 immediately or power servers down until they can. The project's release notes stated the release contains a fix for a critical vulnerability that is actively being exploited. The Bitcoin Red Team, a volunteer security research group, reported the flaw to developers. However, patching alone does not end cleanup requirements - operators must also refresh macaroons and auth strings for other backends, and anyone who generated a hot wallet inside BTCPay should move those funds and recreate them. Integrators should also update NBXplorer, a companion indexing tool, to version 2.6.10.
Both incidents demonstrate how attacks can sidestep Bitcoin's security model and hit the software and habits around it instead. According to reports, phishing remains the costliest threat in crypto, with January's crypto theft losses reaching approximately $400.3 million, and one phishing attack driving over 70% of that figure. The attacks highlight the importance of user verification practices and server security protocols in maintaining Bitcoin self-custody. Google has yet to explain how the fraudulent Trezor ad cleared review, and how quickly the page comes down will determine the extent of damage. The incidents echo a pattern where attacks exploit trust in search ads and merchant server vulnerabilities rather than Bitcoin's core protocol.