Trezor phishing ad drains 24.04 BTC as BTCPay ships critical patch

A counterfeit Trezor site promoted through a Google-sponsored ad appears to have cost one user 24.04 BTC, while BTCPay Server rushed out version 2.4.2 to fix a critical vulnerability already under active exploitation. The two security incidents surfaced within roughly 24 hours of each other and, while neither affected Bitcoin itself, both put funds at immediate risk through surrounding software and user behavior. The Trezor case relied on seed phrase theft rather than any compromise of the hardware wallet, and BTCPay warned operators they must not only patch but also rotate macaroons (Lightning access credentials), refresh other authentication strings, and move funds from any hot wallet created inside the software. Trezor said it escalated the phishing case internally and reported the fake page for takedown. The episode mirrors a fake Uniswap site that drained $400,000 in May. The BTCPay flaw was reported by the Bitcoin Red Team, a volunteer security research group, and integrators were told to update NBXplorer, a companion indexing tool, to version 2.6.10. The incidents underscore a familiar pattern in crypto security: attackers are bypassing the Bitcoin security model by targeting interfaces, infrastructure, and operator habits instead. January crypto theft losses totaled about $400.3 million, with a single phishing attack accounting for more than 70% of that amount.

当サイトの情報はAIを用いて生成されており、正確性を保証するものではありません。 参考情報としてご活用ください。
Trezor phishing ad drains 24.04 BTC as BTCPay ships critical patch - CoinPost Terminal