thousands of users
The cryptocurrency community is on high alert after two significant, concurrent security incidents. First, a sophisticated phishing campaign is targeting users of Trezor hardware wallets by using sponsored Google search ads to direct victims to counterfeit websites. One user reported losing their life savings, valued at over $1.6 million, after being tricked into entering their wallet's recovery seed phrase. The phishing site was deceptively hosted on Google Sites. Concurrently, BTCPay Server, a popular open-source Bitcoin payment processor, issued an emergency security update for a critical vulnerability. The flaw is being actively exploited in the wild, and all users have been urged to update to version 2.4.2 immediately. These incidents highlight the persistent social engineering and software vulnerability risks that target users and merchants in the crypto space.
This report covers two distinct but simultaneous threats to Bitcoin and cryptocurrency users.
sites.google.com to appear more legitimate.This is a classic social engineering attack that exploits user trust in search engine results and a lack of understanding of hardware wallet security principles.
T1566.002 - Spearphishing Link: Although delivered via an ad, the principle is the same: luring a user to a malicious link.T1204.001 - Malicious Link: The user is tricked into clicking the malicious ad link.T1598.003 - Spearphishing Link: The attackers use a web-based delivery mechanism.Details are not public, but for a payment processor, critical vulnerabilities often fall into categories like:
The articles mentioned an on-chain address for the Trezor phishing scam, but did not provide the address itself.
sites.google.com/view/trezor-trez0r.io)docker-compose.ymldocker-compose.yml or server logs for signs of compromise or unusual activity.trezor.io) and only ever access it through your bookmark, not through search engine results.https://trezor.io/ before proceeding.Software Update (D3-SU).URL Analysis (D3-UA).The most critical mitigation for the phishing attack is educating users to never enter their recovery seed phrase on any website.
The only effective mitigation for the BTCPay Server vulnerability is to immediately apply the security patch.
Using web filters that block known phishing sites can provide a layer of protection for users.
The Trezor phishing scam is fundamentally a social engineering attack that preys on user behavior. The most effective countermeasure is to change that behavior through rigorous training, creating a strong 'Personal User Profile' (D3-PUP) of security hygiene. Trezor users must be trained to internalize one absolute rule: the recovery seed phrase is the master key and must NEVER be typed into any digital device (computer, phone) or website, for any reason. It should only be entered on the physical Trezor device itself. Users should be taught to bookmark the official trezor.io site and use that bookmark exclusively, rather than relying on search engine results which can be manipulated with ads. This creates a user profile where suspicion of any request for a seed phrase is the default, automatic reaction, effectively inoculating them against this entire class of attack.
For the BTCPay Server incident, the only acceptable response is immediate Software Update (D3-SU). Since the vulnerability is critical and under active exploitation, administrators of BTCPay Server instances cannot afford to wait for a scheduled maintenance window. They must treat this as an emergency change. The BTCPay team has provided an update script (btcpay-update.sh) to facilitate the process. Admins should first create a backup of their server, then run the update script to move to version 2.4.2 or later. After the update, they should monitor logs for any signs of compromise that may have occurred prior to patching. This incident highlights the responsibility that comes with self-hosting critical financial software: the user is responsible for their own security, and that means applying critical patches without delay.
To provide a layer of automated protection against phishing scams like the one targeting Trezor users, individuals and organizations can use DNS Denylisting (D3-DNSDL). This is often implemented by configuring devices to use a security-focused DNS provider (such as Quad9 or Cloudflare for Families) instead of the default ISP-provided DNS. These services maintain real-time blocklists of known malicious domains, including phishing sites. When a user clicks on the malicious Google Ad and their browser tries to resolve the phishing domain, the DNS service refuses to provide an IP address, preventing the browser from ever connecting to the site. While this is not foolproof, as it relies on the phishing site being identified and added to the blocklist, it provides a valuable, transparent layer of defense that can protect users who might otherwise fall for a scam.
A Trezor user reports losing their life savings to a Google Ad phishing scam.
BTCPay Server issues an emergency security update for a critical vulnerability under active exploitation.

Cybersecurity professional with over 10 years of specialized experience in security operations, threat intelligence, incident response, and security automation. Expertise spans SOAR/XSOAR orchestration, threat intelligence platforms, SIEM/UEBA analytics, and building cyber fusion centers. Background includes technical enablement, solution architecture for enterprise and government clients, and implementing security automation workflows across IR, TIP, and SOC use cases.
CyberNetSec.io uses automation to assist source monitoring, deduplication, observable extraction, and structured intelligence generation. Published analysis follows human-defined editorial standards and adds defensive context including MITRE ATT&CK, D3FEND, STIX, and Sigma where applicable. Read our editorial policy.
Every tactic, technique, and sub-technique used in this threat has been identified and mapped to the MITRE ATT&CK framework for consistent, actionable threat language.
Observables and indicators of compromise (IOCs) have been extracted and cataloged. Risk has been assessed and correlated with known threat actors and historical campaigns.
Detection rules, incident response steps, and D3FEND-aligned mitigation strategies are included so your team can act on this intelligence immediately.
Structured threat data is packaged as a STIX 2.1 bundle and can be visualized as an interactive graph — relationships between actors, malware, techniques, and indicators.
Sigma detection rules are derived from the threat techniques in this article and can be converted for deployment across any major SIEM or EDR platform.