Cryptelio

Hacks & Exploits

Phishing Scam and Exploit Target Bitcoin Users

Cryptelio Editorial Published 7 Aug 2026 · 21:42 UTC

A recent phishing scam targeting Trezor users has reportedly resulted in one individual losing their life savings. The scam was facilitated by a Google-sponsored ad that led users to a counterfeit Trezor page, which was positioned above the legitimate site in search results. The victim, known as David on social media, warned others about the dangers of entering recovery seeds on such fraudulent sites. On-chain data indicates that the wallet associated with the scam received over 24 BTC, valued at approximately $1.6 million, before most of the funds were moved elsewhere.

Trezor has acknowledged the situation and is working to have the fraudulent page removed, urging users to always verify they are on the official website before entering any sensitive information. The hardware itself was not compromised; rather, the attack exploited user trust.

In a separate incident, BTCPay Server, which allows merchants to accept Bitcoin payments, announced a critical vulnerability that is currently being exploited. The team has urged users to update to version 2.4.2 immediately to safeguard their funds. They also recommended that operators refresh their access credentials and move any hot wallet funds to new wallets to mitigate potential losses.

Both incidents highlight the ongoing risks associated with cryptocurrency self-custody. While Bitcoin's protocol remains secure, these attacks demonstrate vulnerabilities in user behavior and software. Phishing continues to be a significant threat in the crypto space, with substantial losses reported in recent months. The effectiveness of responses to these incidents will be crucial in determining the overall impact on users.

New Facts on Cryptocurrency Exploits

  • Hackers siphoned a record $1.1 billion from cryptocurrency protocols in 212 onchain exploits during the first half of the year.
  • North Korea-linked groups accounted for $609 million, or 55%, of those losses.
  • Ethereum and Solana protocols suffered the heaviest losses, approximately $332 million and $326 million respectively.
  • Major breaches included KelpDAO for $292 million and Drift Protocol for $285 million, both linked to the same North Korea cluster.
  • The frequency of attacks increased sharply from 18 in January to 57 in June, with April alone seeing $635 million stolen.
  • Operational security failures, such as privileged key misuse, drove roughly $790 million in damages, significantly outpacing code vulnerabilities.
  • Emerging risks include prompt injection attacks targeting AI agents and novel wallet delegation exploits that bypass traditional defenses.

New Facts on Bitcoin Exploit

  • Bitcoin investors have lost over $88 million due to an exploit in the Coldcard hardware wallet.
  • The exploit is linked to a firmware bug that reduced the randomness of the wallet's secret recovery phrase generation.
  • Researchers identified a third wave of attacks, with 207.7294 BTC drained, bringing the total estimated loss to 1,367.05 BTC across 4,585 addresses.
  • Waves 1 and 2 of the exploit followed similar patterns, but Wave 3 exhibited different behaviors, including the abandonment of shared collectors and a shift to P2WSH addresses.
  • The vulnerable firmware was released on March 17, 2021, around block 674,951, and all identified stolen coins were created after this block.
  • The theft has prompted Coldcard users to take immediate action to protect their funds.

FAQ

What is the recent phishing scam involving Trezor users?

A phishing scam targeting Trezor users involved a counterfeit Trezor page promoted through a Google-sponsored ad, leading to significant financial losses for victims, including one individual who lost their life savings.

How can I verify that I am on the official Trezor website?

Always check the URL in your browser's address bar to ensure it matches the official Trezor website. Avoid clicking on ads or links in search results that could lead to fraudulent sites.

What should I do if I think I have been a victim of a phishing scam?

If you suspect you have fallen victim to a phishing scam, immediately change your passwords, enable two-factor authentication, and contact your wallet provider for further assistance.

What action has BTCPay Server taken regarding the critical vulnerability?

BTCPay Server has announced a critical vulnerability and urged users to update to version 2.4.2 immediately, refresh their access credentials, and move any hot wallet funds to new wallets to protect their assets.

What are the ongoing risks associated with cryptocurrency self-custody?

The ongoing risks include phishing attacks, software vulnerabilities, and user behavior that can lead to significant financial losses. It is crucial for users to remain vigilant and practice safe online habits.

Read story →