Key Takeaways: Two security incidents within 24 hours put Bitcoin user funds at direct risk without touching the protocol itself.
Key Takeaways: Two security incidents within 24 hours put Bitcoin user funds at direct risk without touching the protocol itself.

Two security incidents within 24 hours put Bitcoin user funds at direct risk without touching the protocol itself.
Bitcoin users lost 24.04 BTC worth $1.6 million to a Google-sponsored Trezor phishing ad as BTCPay Server shipped an emergency patch for an actively exploited flaw.
"For everyone reading: always verify that you're using the official Trezor website and never enter your wallet backup into a website or form," the Trezor team urged on X after escalating the case internally and reporting the page for takedown.
The BTCPay Server team issued its own warning on Friday, telling operators to update to version 2.4.2 immediately or power servers down. "This release contains fix of a critical vulnerability that is being actively exploited," the project's release notes state. The Bitcoin Red Team, a volunteer security research group, reported the flaw to developers.
Neither incident breached the Bitcoin protocol itself, but both exploited the software and habits around it. Phishing remains the costliest threat in crypto — January's theft losses reached about $400.3 million, with one phishing attack driving over 70 percent of that figure.
The victim, posting on X under the name David, blamed a sponsored search result on Thursday that placed a counterfeit Trezor page, hosted on Google Sites, above the wallet maker's real website. Anyone who entered a recovery seed into the page handed attackers full control of their wallet.
On-chain data from Mempool shows the harvesting address received 24.04 BTC across 80 transactions, leaving about 0.04 BTC behind. The haul equals roughly $1.6 million at Bitcoin's price near $65,172. The hardware itself was never breached — the attack worked because the seed left the device. The playbook echoes a fake Uniswap phishing site that drained $400,000 from wallets in May.
Google has yet to explain how the fraudulent ad cleared its review process. The incident highlights a persistent vulnerability in search advertising: sponsored results can place malicious pages above legitimate ones, and users who act quickly on the top result may never check the URL.
Operators who patch must also refresh macaroons, the access credentials Lightning nodes rely on, plus auth strings for other backends. Anyone who generated a hot wallet inside BTCPay should move those funds and recreate it. Integrators should also update NBXplorer, a companion indexing tool, to version 2.6.10.
The disclosure lands during a broader security review of Bitcoin infrastructure. The Bitcoin Red Team has flagged 4,962 potential issues across 390 Bitcoin-related projects, classifying 720 as high or critical severity. Zeus Wallet went dark after an attack that shut Lightning channels, and the ongoing Coldcard hardware wallet exploit has resulted in tens of millions of dollars in losses.
BTCPay Server has dealt with critical vulnerabilities before. In 2021, Tesla's security engineering team disclosed a flaw affecting versions 1.0.7.0 and earlier, which the project patched within days. In late 2023, a vulnerability in the LNbank plugin led to actual fund losses, with one user reportedly losing 4 BTC. The current disclosure differs in that the project explicitly confirms active exploitation.
The self-hosted nature of BTCPay Server means no vendor can push this fix onto a merchant's machine. Each unpatched server stays exposed until its own administrator acts, which explains why the project treats a full shutdown as an acceptable interim measure. Namecheap has reportedly processed over $73 million in Bitcoin revenue through the platform, showing the scale of exposure.
How fast the counterfeit Trezor page comes down, and how many BTCPay operators patch in time, will shape the damage from both incidents.
This article is for informational purposes only and does not constitute investment advice.