Skip to content
BTCPay Server Patch Addresses Critical Bitcoin Security Vulnerability

BTCPay Server Patch Addresses Critical Bitcoin Security Vulnerability

First seen 8 Aug 2026, 17:35 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster August 9, 2026 at 15:34 UTC
  • A critical vulnerability in BTCPay Server allows bypassing of TOTP two-factor authentication.
  • Merchants are urged to upgrade to BTCPay version 2.4.2 and NBXplorer version 2.6.10.
  • The vulnerability does not affect Bitcoin's core protocol but poses risks to merchant funds.

BTCPay Server released an emergency update on August 7, 2026, to address a vulnerability (GitHub PR #7491) that allowed cybercriminals to bypass TOTP two-factor authentication via its Greenfield API Basic Authentication. This flaw potentially exposed merchant wallets to theft, as attackers could access accounts using only email and credentials. The vulnerability stems from an authentication check that failed to verify if the two-factor system was enabled. Merchants using BTCPay are advised to upgrade to version 2.4.2 and NBXplorer to version 2.6.10 to mitigate risks. Despite the vulnerability, Bitcoin's market price remains stable at $64,889, with a market cap of $1.3 trillion. The incident highlights the importance of rapid updates in maintaining trust and security in cryptocurrency transactions. BTCPay's self-hosted nature means operators must implement the patch independently.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 44d ago How this analysis works

Timeline

2023-01-31
CVE-2022-32984 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-08-07
Emergency patch released for BTCPay Server
BTCPay Server launched version 2.4.2 to fix a critical vulnerability allowing TOTP bypass.
Cryptopolitan
2026-08-08
Vulnerability actively exploited
Cybercriminals exploited a flaw in BTCPay's authentication, risking merchant funds.
Cryptorank

More articles in this cluster (3)

Following this threat?

Track BTCPay Server and CVE-2022-32984 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed