BTCPay Server, a leading open-source payment processor used by businesses to accept Bitcoin, has released an emergency update after detecting that a security vulnerability in its authenticati
BTCPay Server, a leading open-source payment processor used by businesses to accept Bitcoin, has released an emergency update after detecting that a security vulnerability in its authentication system was being actively exploited, risking the theft of user funds.
Critical API authentication bug discovered
Developers identified that the flaw allows attackers to bypass two-factor authentication (2FA) protections through the server’s Greenfield API using only email and password credentials if accounts registered FIDO2 but used a TOTP authenticator.
The vulnerability stemmed from the system’s failure to properly verify whether 2FA was deployed, checking merely for registered FIDO2 credentials, instead of confirming actual 2FA activation. As a result, while accounts appeared to have 2FA enabled, attackers could access protected API endpoints without needing the additional TOTP code.
Importantly, this issue exists in BTCPay’s application layer and does not impact the underlying Bitcoin protocol or compromise Bitcoin’s cryptography.
BTCPay has urged all operators to immediately upgrade to version 2.4.2, released on August 7, and for integrators to update NBXplorer to version 2.6.10. Both address what BTCPay calls a “critical vulnerability” that has already been exploited in the wild.
BTCPay Server warned that, “Users should migrate to version 2.4.2 without delay and move away from using Basic Authentication, preferring API keys because these allow more granular permission controls.”
Mini dictionary: BTCPay Server is an open-source system that helps merchants accept Bitcoin payments directly, giving users control over their funds without third-party intermediaries.
Market reaction and risk assessment
Despite the security scare, Bitcoin’s market price remains steady near $64,889, showing only a 0.82% day-over-day increase. Market capitalization is largely unchanged at $1.3 trillion, while 24-hour trading volumes have risen just over 20% in the last day. The minimal price movement points to limited immediate impact on the wider Bitcoin ecosystem.
MetricPreviousCurrentChangeBTC Price~$64,359$64,889+0.82%Market Cap$1.29 trillion$1.3 trillion+0.79%24h Volume–+20.98%+20.98%
Analysts note that the vulnerability only affects those using BTCPay Server and does not undermine the security of Bitcoin’s consensus mechanism. Nevertheless, the incident underscores risks inherent in auxiliary systems built around blockchains for payment processing.
Security issues beyond the core blockchain
BTCPay acts as a vital bridge between the Bitcoin blockchain and business payment systems, facilitating invoice generation, payment reception, and wallet management for merchants. If an attacker breaches an operator’s account, financial losses are possible even if Bitcoin’s foundational ledger remains secure.
The system is entirely self-hosted, meaning individual operators are solely responsible for applying updates; no central authority can enforce patches across deployments.
Other payment services have also seen recent breaches. ZEUS, which develops a Lightning wallet for Bitcoin, recently took its infrastructure offline after security issues surfaced—part of a series of incidents affecting Lightning service providers over the past week.
Mini dictionary: Lightning Network is a second-layer protocol for Bitcoin that enables faster and cheaper transactions via off-chain payment channels.
The past week’s incidents highlight the added security risks of wallets, APIs, and payment processors even when Bitcoin’s core blockchain remains uncompromised.
Recent academic research has revealed additional security concerns in Lightning’s single-hop payment protocol and described possible attacks like the “Payout Race,” which exploit timing discrepancies. Another study examined how malicious actors can analyze Lightning channel balances and proposed mitigations to reduce information exposure.
Previous BTCPay vulnerabilities and growing adoption
This is not the first time that BTCPay has addressed a major bug. In January 2023, it patched a severe information leak (CVE-2022-32984) in versions 1.3.0, 1.4.0, and 1.5.3, where attackers could access confidential store details through public Point of Sale apps. Researcher Antoine Poinsot was later awarded $5,000 by BTCPay for responsibly disclosing the flaw.
The current bug, in contrast, relates to authentication bypass in the Greenfield API, letting attackers exploit the absence of proper 2FA checks.
Meanwhile, Bitcoin adoption for merchant payments continues to rise. River’s 2026 report found Bitcoin transaction volumes by merchants grew by 74% in 2025, while Lightning-powered payments surpassed $1 billion monthly, up 300% in that year alone.
Site analytics provider BuiltWith has detected 248 public sites using BTCPay Server, with 74 currently active, likely underestimating broader adoption due to private installations.
According to July 2026 data from 1ML, there are now 6,280 Lightning Network nodes, 21,221 payment channels, and a total capacity surpassing 2,818 BTC, supporting the rapid expansion of Bitcoin’s payment infrastructure.
Security flaws in software around Bitcoin may pose risks on a growing scale, even if the underlying blockchain remains unaffected. Upgrading, reviewing authentication logs, and switching to API keys instead of Basic Authentication are now urgent steps recommended for all BTCPay operators.
The post BTCPay Server issues emergency patch for exploited API security flaw appeared first on COINTURK NEWS.