This website uses cookies
We use cookies to personalise content and ads, to provide social media features and to analyse our traffic. We also share information about your use of our site with our social media, advertising and analytics partners who may combine it with other information that you’ve provided to them or that they’ve collected from your use of their services.
Consent Selection
Details
  • Necessary cookies help make a website usable by enabling basic functions like page navigation and access to secure areas of the website. The website cannot function properly without these cookies.
  • Preference cookies enable a website to remember information that changes the way the website behaves or looks, like your preferred language or the region that you are in.
    • We do not use cookies of this type.

  • Statistic cookies help website owners to understand how visitors interact with websites by collecting and reporting information anonymously.
    • We do not use cookies of this type.

  • Marketing cookies are used to track visitors across websites. The intention is to display ads that are relevant and engaging for the individual user and thereby more valuable for publishers and third party advertisers.
    • We do not use cookies of this type.

  • Unclassified cookies are cookies that we are in the process of classifying, together with the providers of individual cookies.
    • __emg_sidPending
      Maximum Storage Duration: 1 dayType: HTTP Cookie
      __emg_vidPending
      Maximum Storage Duration: 1 yearType: HTTP Cookie
      nl-read-countPending
      Maximum Storage Duration: PersistentType: HTML Local Storage
Cookie declaration last updated on 8/12/26 by Cookiebot
[#IABV2_TITLE#]
[#IABV2_BODY_INTRO#]
[#IABV2_BODY_LEGITIMATE_INTEREST_INTRO#]
[#IABV2_BODY_PREFERENCE_INTRO#]
[#IABV2_BODY_PURPOSES_INTRO#]
[#IABV2_BODY_PURPOSES#]
[#IABV2_BODY_FEATURES_INTRO#]
[#IABV2_BODY_FEATURES#]
[#IABV2_BODY_PARTNERS_INTRO#]
[#IABV2_BODY_PARTNERS#]
About
Cookies are small text files that can be used by websites to make a user's experience more efficient.

The law states that we can store cookies on your device if they are strictly necessary for the operation of this site. For all other types of cookies we need your permission.

This site uses different types of cookies. Some cookies are placed by third party services that appear on our pages.

You can at any time change or withdraw your consent from the Cookie Declaration on our website.

Learn more about who we are, how you can contact us and how we process personal data in our Privacy Policy.

Please state your consent ID and date when you contact us regarding your consent.
NewsLayer.com

BTCPay emergency patch exposes merchant-side Bitcoin security risk

Publié il y a 5 jours 4 min de lecture
BTCPay emergency patch exposes merchant-side Bitcoin security risk

BTCPay issued an emergency patch after a security issue was identified that could affect merchants using its Bitcoin payment infrastructure. The report highlights the importance of promptly applying updates and reviewing operational safeguards around self-hosted payment systems.

Points Clés

  • 01 BTCPay merchants should assess and apply the emergency patch as soon as possible.
  • 02 The issue underscores that payment-server security risks can directly affect merchant operations.
  • 03 Businesses should review access controls, software update processes and transaction monitoring.

An emergency update has been rolled out by BTCPay Server, the open-source software merchants use to accept Bitcoin, due to a vulnerability being exploited to potentially steal funds from users.

As identified in GitHub pull request #7491, this vulnerability enables cybercriminals to circumvent the TOTP two-factor security mechanism through BTCPay’s Greenfield API Basic Authentication. The reason for the vulnerability lies in the fact that the authentication mechanism checked whether valid FIDO2 credentials were registered rather than actually checking whether the two-factor system was even enabled. Thus, the accounts secured with a TOTP authenticator application could access the API using only their email and credentials.

It is important to note that the vulnerability exists within the application layer of BTCPay, not in the Bitcoin (BTC) protocol.

BTCPay has launched version 2.4.2 of its software on August 7 while also advising users to make sure they have updated to the version 2.6.10 of NBXplorer. The upgraded software addresses a “critical vulnerability” that is currently being exploited.

A market that shrugged at the payments scare

Despite the ongoing security concern plaguing the payment system, Bitcoin’s market price and valuation are relatively stable. Bitcoin is trading at about $64,889, which is just a 0.82% increase from the previous day, while its $1.3 trillion market cap has seen a rise of only 0.79%. Even though trading activity has been more active with the 24-hour volume increasing 20.98%, the fairly stable price and market cap indicate that the incident has not yet had an impact on Bitcoin’s overall market valuation.

The subdued response is understandable. The BTCPay vulnerability affects only individual merchants and operators, not Bitcoin’s consensus rules or cryptography.

However, that does not mean it is insignificant. BTCPay creates a link between the Bitcoin network and the payment systems of businesses issuing invoices, receiving payments and managing the wallets. Therefore, in case of an attack on the operator account, it becomes possible to cause real monetary losses despite the proper functioning of the Bitcoin blockchain.

What BTCPay told operators to do

The immediate solution to this problem is simple: upgrade BTCPay Server to version 2.4.2 and, for integrators, upgrade NBXplorer to version 2.6.10.

According to BTCPay, it is better to use application programming interface (API) keys instead of Basic Authentication because permissions can be limited more effectively. The new patch has also introduced changes to the authentication process so that it will be able to check whether 2FA is really active, thereby closing the gap which enabled TOTP-protected accounts to avoid the second authentication level.

Since BTCPay is self-hosted, operators cannot depend on a central provider to implement the patch for them.

A third strike for Bitcoin’s payment plumbing

BTCPay’s announcement comes after a tumultuous week for Bitcoin’s payment system. Cryptopolitan had reported earlier that ZEUS, the provider of a Lightning wallet, had rendered its payment infrastructure inactive because of a problem that occurred involving the security of the system, while other Lightning service providers also got affected.

The occurrences do not indicate that the Bitcoin payment protocols are failing in any way. They do show, however, how much additional security risk is introduced by the software built around the blockchain.

A 2024 study by researchers from Northeastern University and TU Delft used formal modeling to identify security problems in Lightning’s single-hop payment protocol, including a new “Payout Race” attack.

A separate 2026 study examined balance-discovery attacks, finding that attackers can infer information about Lightning channel balances. Its proposed mitigation reduced information gain by as much as 62% in simulations.

Both the studies reveal a more significant truth: the security of Bitcoin does not merely depend on the blockchain. Wallets, APIs, payment processors, as well as the Lightning infrastructure all introduce additional points of vulnerabilities.

Not BTCPay’s first critical bug

BTCPay has previously encountered serious vulnerabilities. In January 2023, it reported about CVE-2022-32984, a critical information leak that affected BTCPay’s versions 1.3.0, 1.4.0 and 1.5.3.

The flaw has the potential to leak sensitive store details via publicly available Point of Sale applications, possibly exposing an xpub and Lightning credentials tied to an external node. BTCPay resolved this problem in version 1.5.4 and later rewarded researcher Antoine Poinsot with a bounty of $5,000.

The difference here is clear: the 2023 attack was an information leak while the recent vulnerability has to do with authentication issues that circumvent TOTP security through the Greenfield API.

Why merchants have more to lose now

Things are heating up as Bitcoin becomes increasingly valuable for payments. Research from River published in February 2026 noted average Bitcoin usage by merchants increased by 74% in 2025 alone while Lightning usage increased by 300% and went over $1 billion in monthly volume.

The surrounding infrastructure is also significant. BuiltWith has detected 248 sites that use BTCPay Server, which include 74 active ones, although these numbers don’t include private or other undetectable installations.

Additionally, the latest snapshot by 1ML shows there are 6,280 Lightning nodes, 21,221 channels, and the current network capacity of 2,818.49 BTC.

That scale makes vulnerabilities in the surrounding infrastructure all the more severe, even if the base layer of Bitcoin hasn’t been affected in any way.

The takeaway from BTCPay does not suggest that Bitcoin itself is flawed. Instead, it indicates that businesses built on Bitcoin inherit a broader security burden. The blockchain may still be functioning, but the applications used by merchants may become a point of failure.

For BTCPay operators, the priority is simple: upgrade to version 2.4.2, evaluate authentication logs and access logs for signs of compromise, and to use specific API keys instead of Basic Authentication when possible.

 

Attribution

Originally reported by Cryptopolitan

Dernière Minute

Ne manquez aucune actualité de dernière minute

Les grandes nouvelles vont vite — recevez-les en premier sur X et Telegram.

Get stories like this, daily.

Daily crypto + regulation intelligence, straight to your inbox. Free.

Articles Liés