Trezor phishing ad drains 24.04 BTC as BTCPay ships critical patch

A counterfeit Trezor site promoted through a Google-sponsored ad appears to have cost one user 24.04 BTC, while BTCPay Server rushed out version 2.4.2 to fix a critical vulnerability already under active exploitation. The two security incidents surfaced within roughly 24 hours of each other and, while neither affected Bitcoin itself, both put funds at immediate risk through surrounding software and user behavior. The Trezor case relied on seed phrase theft rather than any compromise of the hardware wallet, and BTCPay warned operators they must not only patch but also rotate macaroons (Lightning access credentials), refresh other authentication strings, and move funds from any hot wallet created inside the software. Trezor said it escalated the phishing case internally and reported the fake page for takedown. The episode mirrors a fake Uniswap site that drained $400,000 in May. The BTCPay flaw was reported by the Bitcoin Red Team, a volunteer security research group, and integrators were told to update NBXplorer, a companion indexing tool, to version 2.6.10. The incidents underscore a familiar pattern in crypto security: attackers are bypassing the Bitcoin security model by targeting interfaces, infrastructure, and operator habits instead. January crypto theft losses totaled about $400.3 million, with a single phishing attack accounting for more than 70% of that amount.

本网站上的信息是使用AI生成的,我们无法保证其准确性。 请仅作为参考信息使用。