Cryptorank BTCPay Server Patch Addresses Critical Bitcoin Security Vulnerability
Article Content
- •A critical vulnerability in BTCPay Server allows bypassing of TOTP two-factor authentication.
- •Merchants are urged to upgrade to BTCPay version 2.4.2 and NBXplorer version 2.6.10.
- •The vulnerability does not affect Bitcoin's core protocol but poses risks to merchant funds.
BTCPay Server released an emergency update on August 7, 2026, to address a vulnerability (GitHub PR #7491) that allowed cybercriminals to bypass TOTP two-factor authentication via its Greenfield API Basic Authentication. This flaw potentially exposed merchant wallets to theft, as attackers could access accounts using only email and credentials. The vulnerability stems from an authentication check that failed to verify if the two-factor system was enabled. Merchants using BTCPay are advised to upgrade to version 2.4.2 and NBXplorer to version 2.6.10 to mitigate risks. Despite the vulnerability, Bitcoin's market price remains stable at $64,889, with a market cap of $1.3 trillion. The incident highlights the importance of rapid updates in maintaining trust and security in cryptocurrency transactions. BTCPay's self-hosted nature means operators must implement the patch independently.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (3)
Following this threat?
Track BTCPay Server and CVE-2022-32984 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical WSO2 API Manager Vulnerability Under Active Exploitation A critical vulnerability (CVE-2026-5430) in WSO2 API Manager is being actively exploited, allowing unauthenticated attackers to forge admin tokens via JWT authentication bypass. This flaw, which has a CVSS score of 10.0, affects multiple WSO2 products including API Manager, Universal Gateway, Traffic Manager, and API…
Critical Linux Kernel Vulnerability CVE-2025-39682 Under Active Exploitation A critical vulnerability (CVE-2025-39682) in the Linux kernel allows remote code execution through mishandling of zero-length TLS records. This flaw affects kTLS-enabled hosts running vulnerable kernel versions, exposing them to attackers without authentication. CISA added this vulnerability to its Known Exploited…