BTCPay Emergency Patch Fixes Critical Vulnerability in Bitcoin Security
A recent emergency patch has been rolled out by BTCPay Server to address a critical vulnerability in its system, which could potentially allow cybercriminals to steal funds from users.
The issue, identified as CVE-2023-32984, affects the TOTP two-factor security mechanism through BTCPay's Greenfield API Basic Authentication. It allows attackers to bypass the second authentication level and access the API using only an email and credentials.
BTCPay has advised users to upgrade to version 2.4.2 of its software and NBXplorer to version 2.6.10, as these versions address the vulnerability. The company also recommends using application programming interface (API) keys instead of Basic Authentication for better security.
The incident highlights the importance of maintaining robust security measures in the Bitcoin ecosystem, especially as the cryptocurrency becomes increasingly valuable for payments. Merchants and operators are urged to prioritize upgrading their systems and implementing secure authentication practices to prevent potential losses.