Industry News

BTCPay Server Rushes Out Emergency Patch After Two-Factor Bypass Found

Cryptopolitan · 8 Aug 2026
Key Takeaway If your business uses BTCPay Server to accept Bitcoin, update immediately and regularly check for security advisories on self-hosted financial software.

BTCPay Server, a popular open-source platform used by merchants to accept Bitcoin payments, has issued an emergency security update after discovering a vulnerability that attackers were actively exploiting. The flaw, detailed in a GitHub pull request, allowed cybercriminals to bypass the platform's TOTP (time-based one-time password) two-factor authentication protection through its Greenfield API Basic Authentication feature.

Two-factor authentication is meant to be a critical safeguard, so a bypass of this kind is particularly serious for any business handling cryptocurrency payments. Merchants using BTCPay Server to process Bitcoin transactions were left exposed to potential theft of funds until the patch was applied.

Any Australian small business using BTCPay Server or similar self-hosted payment infrastructure should treat this as an urgent reminder to keep software updated. Open-source financial tools offer flexibility and control, but that responsibility also means businesses must actively monitor for security advisories rather than relying on a third party to manage updates automatically.

Summarised by CISO AI from Cryptopolitan. We link back to every original so you can read it yourself.