BTCPay Server Patch Addresses Critical Bitcoin Security Vulnerability

BTCPay Server Patch Addresses Critical Bitcoin Security Vulnerability

First seen 8 Aug 2026, 17:35 UTC CryptopolitanCryptorankarxiv.org 87% similarity 72.0

Article Content

Browse articles
ThreatCluster

BTCPay Server released an emergency update on August 7, 2026, to address a vulnerability (GitHub PR #7491) that allowed cybercriminals to bypass TOTP two-factor authentication via its Greenfield API Basic Authentication. This flaw potentially exposed merchant wallets to theft, as attackers could access accounts using only email and credentials. The vulnerability stems from an authentication check that failed to verify if the two-factor system was enabled. Merchants using BTCPay are advised to upgrade to version 2.4.2 and NBXplorer to version 2.6.10 to mitigate risks. Despite the vulnerability, Bitcoin's market price remains stable at $64,889, with a market cap of $1.3 trillion. The incident highlights the importance of rapid updates in maintaining trust and security in cryptocurrency transactions. BTCPay's self-hosted nature means operators must implement the patch independently.

Key Points: • A critical vulnerability in BTCPay Server allows bypassing of TOTP two-factor authentication. • Merchants are urged to upgrade to BTCPay version 2.4.2 and NBXplorer version 2.6.10. • The vulnerability does not affect Bitcoin's core protocol but poses risks to merchant funds.

ThreatCluster AI How this analysis works

Timeline

2023-01-31
CVE-2022-32984 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-08-07
Emergency patch released for BTCPay Server
BTCPay Server launched version 2.4.2 to fix a critical vulnerability allowing TOTP bypass.
Cryptopolitan
2026-08-08
Vulnerability actively exploited
Cybercriminals exploited a flaw in BTCPay's authentication, risking merchant funds.
Cryptorank

Community

Browse all →