AltcoinBuzzAltcoinBuzz
Subscribe
  • Crypto News
  • Crypto Research
  • Technical Analysis
AltcoinBuzzAltcoinBuzz

An independent digital media outlet delivering crypto research, news, and technical analysis to a community of 600,000+ users.

Follow us on:

Discover

  • Crypto Research
  • Crypto News
  • Technical Analysis
  • Key Opinions
  • Upcoming Launches

Categories

  • Bitcoin BTC
  • RWA
  • Technology
  • Altcoins
  • Regulation

Company

  • Affiliates
  • Partners & Sponsors
  • Careers
  • Contact
  • Terms of Use
  • Subscription Terms
  • About the ALTCOINBUZZ
  • Privacy Policy
  • Contact ALTCOINBUZZ
  • Advertise with us

Copyright 2026 ALTCOINBUZZ. All rights reserved.Something is buzzzzzzzing.
HomeCrypto ResearchTrezor phishing ad and BTCPay exploit put Bitcoin users at risk
Crypto ResearchBitcoin BTCTechnology

Trezor phishing ad and BTCPay exploit put Bitcoin users at risk

A fake Trezor ad reportedly drained about $1.6 million in Bitcoin, while BTCPay Server patched a critical flaw under active exploitation.

BBikash Deka•Aug 8, 2026
Trezor phishing scam
MentionedBTC$65,002.00+0.50%

Two separate security incidents have put Bitcoin users and merchants on alert, with a Trezor phishing scam reportedly stealing millions of dollars and BTCPay Server releasing an emergency security update for a critical vulnerability.

The incidents happened within roughly 24 hours of each other. Importantly, neither attack compromised the Bitcoin network itself. Instead, attackers targeted the software, services, and user behavior around Bitcoin.

Fake Trezor Ad Drains Bitcoin From User

A Bitcoin user has reportedly lost their life savings after clicking a fraudulent Trezor-sponsored ad on Google.

The victim, who posted about the incident on X, said the fake advertisement appeared above Trezor's legitimate website in Google search results. The fraudulent page was hosted through Google Sites and was designed to look like the official Trezor website.

The scam asked users to enter their wallet recovery seed.

Once a recovery seed is entered into a phishing website, attackers can use it to take complete control of the associated wallet. A hardware wallet itself does not need to be hacked for this type of attack to succeed.

On-chain data linked to the reported wallet shows that it received approximately 24.04 BTC across 80 transactions. At Bitcoin's price of around $65,172, the funds were worth roughly $1.6 million.

Most of the Bitcoin has since moved out of the wallet, leaving only around 0.04 BTC behind.

Trezor said it escalated the incident internally and reported the fraudulent website for removal.

The Trezor Hardware Was Not Hacked

The incident is important because the Trezor device itself was not compromised.

Instead, the attack relied on social engineering. The victim was tricked into giving away the recovery seed, which effectively gave the attacker access to the wallet.

This is one of the most important rules of crypto self-custody: a recovery seed should never be entered into a website, app, or form.

The incident is similar to other phishing attacks that have targeted crypto users by creating fake versions of trusted websites and services.

BTCPay Server Releases Emergency Security Patch

A separate security incident affected BTCPay Server, an open-source platform that allows merchants to accept Bitcoin payments.

BTCPay Server warned operators on Friday about a critical vulnerability that was already being exploited and urged them to take immediate action.

The project recommended that operators upgrade to version 2.4.2 immediately. Those unable to update were advised to shut down their BTCPay servers until they could apply the fix.

The vulnerability was reported to BTCPay developers by the Bitcoin Red Team, a volunteer group focused on finding security weaknesses across Bitcoin-related software.

However, updating BTCPay Server is not the only step operators need to take.

Operators should also:

  • Refresh macaroons, which are credentials used by Lightning nodes.
  • Update authentication credentials for other connected backends.
  • Move funds from any hot wallets created inside BTCPay Server.
  • Create new hot wallets after securing the affected system.
  • Update NBXplorer, a companion indexing service, to version 2.6.10.

These additional steps are important because simply installing the patch may not remove credentials that attackers could have already accessed.

Why These Bitcoin Security Incidents Matter

The Trezor phishing attack and the BTCPay Server vulnerability used very different methods.

The Trezor incident relied on social engineering and a fake search advertisement, while the BTCPay incident involved a vulnerability in software used to process Bitcoin payments.

However, both attacks targeted the infrastructure surrounding Bitcoin rather than the Bitcoin protocol itself.

This distinction matters. Bitcoin's underlying network was not hacked in either incident. Instead, attackers exploited weaknesses in websites, software, credentials, and user behavior.

For Bitcoin users, the Trezor incident is another reminder that recovery phrases are the most sensitive piece of information in a self-custody wallet. Anyone who obtains a seed phrase can potentially control the funds associated with it.

For BTCPay operators, the incident highlights the importance of applying security updates quickly and rotating credentials after a vulnerability has been actively exploited.

Phishing Remains a Major Crypto Threat

Phishing continues to be one of the biggest risks facing cryptocurrency users.

Attackers often imitate trusted exchanges, wallet providers, payment services, and other crypto platforms. Search advertisements can make these scams even harder to spot because fraudulent pages may appear alongside legitimate results.

The latest Trezor incident also raises questions about how fraudulent advertisements are able to pass advertising checks and appear prominently in search results.

For users, the safest approach is to avoid entering recovery phrases into websites entirely and access wallet services through verified official channels.

Meanwhile, BTCPay operators should treat the latest vulnerability as an urgent security issue and make sure affected servers, credentials, and wallets are properly secured.

Bitcoin Was Not Hacked, But Users Remain the Target

Neither incident represents a compromise of the Bitcoin network.

Instead, they show how attackers can target the tools and people surrounding the network. A fake Trezor website can steal a recovery phrase, while a vulnerable payment server can expose merchant infrastructure.

For Bitcoin users, the key lesson is simple: never share your recovery seed, even with a website that looks legitimate. For BTCPay operators, installing the latest security updates and rotating potentially exposed credentials should be treated as a priority.

The information discussed by Altcoin Buzz is not financial advice. This is for educational, entertainment, and informational purposes only. Any information or strategies are thoughts and opinions relevant to the accepted levels of risk tolerance of the writer/reviewers and their risk tolerance may be different than yours. We are not responsible for any losses that you may incur as a result of any investments directly or indirectly related to the information provided. Bitcoin and other cryptocurrencies are high-risk investments so please do your due diligence. This post is sponsored by Market Across.

Copyright Altcoin Buzz Pte Ltd.

Related

Bitcoin BIP-110 fork replay attack showing how fork coin transactions could affect real BTC
TechnologyBitcoin BTC
Aug 8, 2026

Bitcoin holders could lose real BTC in a BIP-110 fork replay attack

Bitcoin holders could lose real BTC if they sell coins from a BIP-110 fork before replay protection is active. Developers urge caution if the chain splits.

BTC
Bikash Deka
Microsoft warns that hackers are using BNB Smart Chain to distribute malware through fake CAPTCHA attacks.
Technology
Aug 7, 2026

Microsoft warns hackers are using BNB Chain to spread malware

Microsoft has uncovered a new malware campaign that uses BNB Smart Chain to hide malicious code. The attack tricks users into running fake CAPTCHA commands that can install password-stealing malware and remote access tools.

BNB
Bikash Deka
Coinfest Asia 2026 brings together global Web3 leaders, crypto companies, builders, traders, and institutions in Bali, Indonesia.
Key Opinions
Aug 6, 2026

Coinfest Asia 2026 Connects Institutions, Builders and Traders to The World’s Crypto Festival

Coinfest Asia 2026 returns to Bali on August 20–21 with dedicated tracks for institutions, builders, and traders, connecting the global Web3 community.

Shash
David
David
@ReallyBadDay99
·Follow

Hey @Trezor, just lost my life savings. Top sponsored Google result for 'Trezor wallet' is a phishing site! The scam page (sites.google.com/view/start-tre…) is vacuuming up millions. Harvesting address is currently sitting at: bc1qrz33mr7tx8wrpcs2pxrvv83hqwpm907s9shkz4 @zachxbt @CertiK

7:56 PM · Aug 6, 2026
1.5K
Reply
Read 251 replies
BTCPay Server
BTCPay Server
@BtcpayServer
·Follow

There is a critical vulnerability being actively exploited on BTCPay Server, which can result in the loss of funds. Please update your BTCPayServer to 2.4.2 by going to Admin Dashboard -> Server -> Maintenance -> Update & verify the 2.4.2 version string in the footer. If you Show more

3:51 PM · Aug 7, 2026
2.5K
Reply
Read 206 replies