BTCPay emergency patch exposes merchant-side Bitcoin security risk
Aug 8, 2026
< 1 min read
by Micah Abiodun
for CryptoPolitan

Share:
AI Overview
BTCPay Server, the open-source Bitcoin merchant payment software, issued an emergency update after a vulnerability (GitHub PR #7491) was actively exploited to bypass TOTP two-factor authentication via its Greenfield API Basic Authentication, allowing attackers to potentially steal funds from merchants. The patch addresses a critical crypto security risk for merchant wallets and payment providers, underscoring the need for rapid protocol updates to protect adoption and custody, and indicating short-term negative impact on trust.
Bearish
An emergency update has been rolled out by BTCPay Server, the open-source software merchants use to accept Bitcoin, due to a vulnerability being exploited to potentially steal funds from users. As identified in GitHub pull request #7491, this vulnerability enables cybercriminals to circumvent the TOTP two-factor security mechanism through BTCPay’s Greenfield API Basic Authentication. The...
