Skip to content
Back to Guavy Wire
Crypto

BTCPay Emergency Patch Fixes Critical Vulnerability in Bitcoin Security

Instruments
BTC BTCP
Share

A recent emergency patch has been rolled out by BTCPay Server to address a critical vulnerability in its system, which could potentially allow cybercriminals to steal funds from users.

The issue, identified as CVE-2023-32984, affects the TOTP two-factor security mechanism through BTCPay's Greenfield API Basic Authentication. It allows attackers to bypass the second authentication level and access the API using only an email and credentials.

BTCPay has advised users to upgrade to version 2.4.2 of its software and NBXplorer to version 2.6.10, as these versions address the vulnerability. The company also recommends using application programming interface (API) keys instead of Basic Authentication for better security.

The incident highlights the importance of maintaining robust security measures in the Bitcoin ecosystem, especially as the cryptocurrency becomes increasingly valuable for payments. Merchants and operators are urged to prioritize upgrading their systems and implementing secure authentication practices to prevent potential losses.

More on Crypto

Disclaimer: Guavy is a data and market intelligence provider, not an investment advisor. The information, signals, and market analysis provided by the Guavy API and related services are for informational purposes only and are not intended as financial advice, investment recommendations, or an endorsement of any particular trading strategy. Trading in volatile markets, including cryptocurrency, carries significant risk and may not be suitable for all investors. Past performance is not indicative of future results. Users should consult with a qualified financial professional before making any investment decisions. Guavy makes no guarantee of trading profits or financial returns.

Market sentiment intelligence for apps, funds & agents

Location

729 55 Ave SW
Calgary AB T2V 0G4
Canada

© 2026 Guavy Inc