EN ▼
Favorites
My Favorites
View All
Market Cap Price 24h%

Disclaimer: Content does not constitute investment advice. Trading involves risks—please invest with caution!

BTCPay emergency patch exposes merchant bitcoin security risks

2026-08-08 12:07:29
Bookmark

Emergency update for BTCPay Server: fixes vulnerabilities that can be used to steal money

Open source software BTCPay Server has released an emergency update. The software is used by merchants to receive Bitcoin payments, and the update is due to a vulnerability that could be exploited to steal user funds.

According to information in GitHub pull request #7491, this vulnerability allows cybercriminals to bypass the TOTP two-factor security mechanism through BTCPay's Greenfield API basic authentication mechanism. The root cause of the problem is that the authentication mechanism only checks whether valid FIDO2 credentials are registered, but does not actually check whether the dual-factor system is enabled. Therefore, accounts protected using the TOTP Verifier application can access the API based on their mailbox and password alone.

It should be noted that this vulnerability exists in the application layer of BTCPay, not the Bitcoin (BTC) protocol itself.

BTCPay released software version 2.4.2 on August 7, and users are advised to ensure that NBXplorer has been updated to version 2.6.10. The upgraded software fixed a "critical vulnerability" that has now been exploited.

Market response to payment security incidents is flat

Although payment systems face ongoing security issues, Bitcoin's market price and valuation are relatively stable. Bitcoin is currently trading at approximately US$64,889, up only 0.82% from the previous day, and its US$1.3 trillion market value has only increased by 0.79%. Despite increased trading activity, with 24-hour trading volume rising by 20.98%, relatively stable prices and market capitalizations suggest that the incident has not yet had an impact on Bitcoin's overall market valuation.

This bland reaction is understandable. The BTCPay vulnerability only affects individual merchants and operators and does not involve Bitcoin's consensus rules or cryptographic principles.

However, this does not mean that the vulnerability is insignificant. BTCPay establishes a connection between the Bitcoin network and companies 'payment systems for issuing invoices, receiving payments and managing wallets. Therefore, once the operator's account is attacked, even if the Bitcoin blockchain itself is operating normally, actual economic losses may be caused.

BTCPay recommends actions for operators

The immediate solution to the current problem is simple: upgrade BTCPay Server to version 2.4.2, and for integrators, upgrade NBXplorer to version 2.6.10.

According to BTCPay, it is recommended to use application programming interface (API) keys rather than basic authentication because they can more effectively restrict permissions. The new patch also improves the authentication process, making it possible to check whether two-factor authentication is actually enabled, closing a vulnerability that allows TOTP-protected accounts to bypass second-layer authentication.

Because BTCPay is self-managed software, operators cannot rely on centralized providers to deploy patches for it.

Another shock to Bitcoin payment infrastructure

BTCPay's announcement follows a week of turmoil in the Bitcoin payment system. It has been previously reported that Lightning Internet wallet provider ZEUS has suspended its payment infrastructure due to system security issues, and other Lightning Internet service providers have also been affected.

These incidents do not mean that the Bitcoin payment protocol itself is flawed. But they do show that software built around blockchain introduces additional security risks.

In 2024, researchers at Northeastern University and Delft University of Technology discovered security issues in the Lightning Network single-hop payment protocol through formal modeling, including a new type of attack called "Payout Race."

Another 2026 study analyzed balance discovery attacks and found that attackers could infer balance information on Lightning network channels. Its proposed mitigation plan reduced the amount of information captured by as much as 62% in simulations.

These two studies reveal a more important fact: Bitcoin's security does not depend solely on the blockchain. Wallets, APIs, payment processors, and Lightning network infrastructure have all introduced additional vulnerability points.

This is not the first time BTCPay has seen a critical vulnerability

BTCPay has also encountered serious vulnerabilities before. In January 2023, it reported CVE-2022-32984, a serious information breach that affected versions 1.3.0, 1.4.0, and 1.5.3 of BTCPay.

This vulnerability could leak sensitive store details through a public point-of-sale application, potentially exposing xpub and Lightning network credentials associated with external nodes. BTCPay solved the issue in version 1.5.4 and subsequently provided researcher Antoine Poinsot with a $5,000 vulnerability bounty.

The difference between the two vulnerabilities is obvious: the 2023 attack was an information disclosure, while the recent vulnerability involved authentication issues that could bypass the TOTP security mechanism through the Greenfield API.

Why merchants face greater risks today

As Bitcoin becomes more and more valuable in the payment space, the situation is becoming increasingly serious. Research released by River in February 2026 pointed out that in 2025 alone, average usage of Bitcoin by merchants increased by 74%, while usage of Lightning Network increased by 300%, with monthly transaction volume exceeding US$1 billion.

The scale of related infrastructure is also very large. According to testing, 248 websites use BTCPay Server, of which 74 are active, although these numbers do not include private or undetectable installation instances.

In addition, the latest data shows that there are currently 6,280 Lightning network nodes, 21,221 channels, and the current network capacity is 2,818.49 BTC.

This scale makes vulnerabilities in surrounding infrastructure even more serious, even if Bitcoin's underlying network has not been affected in any way.

The BTCPay incident does not imply that Bitcoin itself is flawed. Instead, it suggests that businesses built on top of Bitcoin bear a broader security burden. Blockchain may still be running normally, but applications used by merchants could become failure points.

For BTCPay operators, the top priority is simple: upgrade to version 2.4.2, check the authentication logs and access logs for signs of intrusion, and use specific API keys instead of basic authentication if possible.

Disclaimer:

All content published on this website, including hyperlinks, related applications, forums, blogs, and other media accounts, originates from third-party platforms and their users. CoinMarketInsight makes no representations or warranties of any kind regarding the website or its content. All blockchain-related data and materials are provided for informational and research purposes only and do not constitute financial, legal, or investment advice. Users and third parties are solely responsible for the content they publish. CoinMarketInsight shall not be liable for any losses arising from the use of this website. You should exercise caution and conduct your own independent research, review, analysis, and verification before making any decisions.

Read Full Article
More News
TOP

TOP