Bitcoin Users Targeted: Trezor Phishing Ad and BTCPay Server Flaw Under Active Attack
A cryptocurrency user has reported losing their life savings after clicking on a Google-sponsored advertisement that impersonated Trezor, a popular hardware wallet brand. Phishing ads like this typically lead victims to fake websites designed to steal wallet credentials or trick users into revealing recovery phrases, giving attackers direct access to funds.
Separately, BTCPay Server, an open-source payment processor used by many merchants to accept Bitcoin, has released an emergency patch for a critical security flaw. The vulnerability was already being actively exploited by attackers before the fix was issued, meaning businesses running unpatched versions were at real risk of compromise.
While these incidents involve cryptocurrency specifically, they highlight a broader lesson for any business: sponsored search ads can be weaponised by criminals to impersonate trusted brands, and software left unpatched becomes an open door for attackers. Small businesses using any third-party payment or financial software should treat security updates as urgent, not optional.