Bitcoin Forum
August 09, 2026, 10:20:05 AM *
News: COLDCARD users only: critical vulnerability risks funds stored on COLDCARD devices; immediate action required
 
   Home   Help Search Login Register More  
Pages: « 1 [2]  All
  Print  
Author Topic: Critical vulnerability discovered in BTCPay Server  (Read 223 times)
DanWalker
Hero Member
*****
Offline

Activity: 2688
Merit: 580


Leading Crypto Sports Betting & Casino Platform


View Profile
August 08, 2026, 08:52:18 AM
 #21

As open source projects are being targeted now, what then is our last line of defense? A lot of people suggested in other posts that using multisig wallets and generating the seed phrase offline and others, but are these methods enough to protect people's money. I really do not feel at ease when I see  with open source system because they were supposed to be rhe safest means of storing Bitcoin.

In fact it is not correct to say that Open source mean the safest. Also finding a vulnerability does not mean that open source is unsafe.

Big advantage of open source is that you can easily inspect or audit the code and even if a vulnerability is found, it can be patched very quickly. But open source will never free us from security responsibility.

Anyway, the most sensible approach for me is to reduce exposure of our fund. We can use small hot-wallet for daily spending. And for big saving we should use properly configured multisig. I agree with you, we should practice keeping seeds offline and keeping backups in separate place. And we should not keep more BTC than necessary in any internet-facing service.

..Stake.com..   ▄████████████████████████████████████▄
   ██ ▄▄▄▄▄▄▄▄▄▄            ▄▄▄▄▄▄▄▄▄▄ ██  ▄████▄
   ██ ▀▀▀▀▀▀▀▀▀▀ ██████████ ▀▀▀▀▀▀▀▀▀▀ ██  ██████
   ██ ██████████ ██      ██ ██████████ ██   ▀██▀
   ██ ██      ██ ██████  ██ ██      ██ ██    ██
   ██ ██████  ██ █████  ███ ██████  ██ ████▄ ██
   ██ █████  ███ ████  ████ █████  ███ ████████
   ██ ████  ████ ██████████ ████  ████ ████▀
   ██ ██████████ ▄▄▄▄▄▄▄▄▄▄ ██████████ ██
   ██            ▀▀▀▀▀▀▀▀▀▀            ██ 
   ▀█████████▀ ▄████████████▄ ▀█████████▀
  ▄▄▄▄▄▄▄▄▄▄▄▄███  ██  ██  ███▄▄▄▄▄▄▄▄▄▄▄▄
 ██████████████████████████████████████████
▄▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▄
█  ▄▀▄             █▀▀█▀▄▄
█  █▀█             █  ▐  ▐▌
█       ▄██▄       █  ▌  █
█     ▄██████▄     █  ▌ ▐▌
█    ██████████    █ ▐  █
█   ▐██████████▌   █ ▐ ▐▌
█    ▀▀██████▀▀    █ ▌ █
█     ▄▄▄██▄▄▄     █ ▌▐▌
█                  █▐ █
█                  █▐▐▌
█                  █▐█
▀▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▀█
▄▄█████████▄▄
▄██▀▀▀▀█████▀▀▀▀██▄
▄█▀       ▐█▌       ▀█▄
██         ▐█▌         ██
████▄     ▄█████▄     ▄████
████████▄███████████▄████████
███▀    █████████████    ▀███
██       ███████████       ██
▀█▄       █████████       ▄█▀
▀█▄    ▄██▀▀▀▀▀▀▀██▄  ▄▄▄█▀
▀███████         ███████▀
▀█████▄       ▄█████▀
▀▀▀███▄▄▄███▀▀▀
..PLAY NOW..
Pmalek (OP)
Legendary
*
Offline

Activity: 3584
Merit: 9433



View Profile
August 08, 2026, 03:40:11 PM
 #22

The ColdCard case could be the beginning of something good and so far it's looking like it, maybe from now on the main focus will be 100% on the vulnerabilities on the Blockchain system.
It's always going to be a race between good actors vs bad actors. The Coldcard case has shown that both types exist (as if we didn't know that before). Some people use AI to help them take advantage of vulnerabilities to steal money. Others use it to help discover and correct problems.


And for big saving we should use properly configured multisig. I agree with you, we should practice keeping seeds offline and keeping backups in separate place.
If the keys are not generated with enough entropy, a properly generated multisig won't help you. If 2/3 keys in a multisig setup were generated by Coldcard, hackers would have the needed quorum to empty such addresses. Keeping your keys offline won't help either. Coldcard keys were offline.


Anyways, we are moving into of topic territory here so let's get back to BTCPay Server stuff.

Video instruction for updating BTCPay Server on Umbrel:
https://x.com/nmfretz/status/2085966668011028533

Two addresses connected to the theft of funds from BTCPay Server have been identified. Luckily, the scammers haven't stolen much. One contains 1.74760889 BTC, the other 0.46608022 BTC
https://x.com/pavlenex/status/2086012989262401863

▄▄███████████████████▄▄
▄███████████████████████▄
████████████████████████
█████████████████████████
████████████████████████
████████████▀██████▀████
████████████████████████
█████████▄▄▄▄███████████
██████████▄▄▄████████████
████████████████████████
████████████████▀▀███████
▀███████████████████████▀
▀▀███████████████████▀▀
 
 EARNBET 
| 🏀
 
🏈 🏓
 
🎯 🥊
 
 🎾
 
 🏐
 
🏏 🏎️
|


███████▄▄███████████
████▄██████████████████
██▀▀███████████████▀▀███
▄████████████████████████
▄▄████████▀▀▀▀▀████████▄▄██
███████████████████████████
█████████▌██▀████████████
███████████████████████████
▀▀███████▄▄▄▄▄█████████▀▀██
▀█████████████████████▀██
██▄▄███████████████▄▄███
████▀██████████████████
███████▀▀███████████

....HIGHEST....
VIP REWARDS

  G U A R A N T E E D   
| 
 🜲 
KING OF
THE CASTLE

$200K in prizes
| 
..PLAY NOW..
logfiles
Copper Member
Legendary
*
Offline

Activity: 2800
Merit: 2383



View Profile WWW
August 08, 2026, 03:58:21 PM
 #23

<...>
The warning shots were already there, but the hackers were most targeting smart contracts of different DeFi and crypto bridges. They had all the time to use AI to detect some vulnerabilities and have them fixed

I guess they are not going to act accordingly though I feel like there will always be avulnariabilty waiting to be discovered. The issue is who discovers it. The good actor or the bad actor?

▄███████████████████████▄
███████████████████████
████████████▀▀██████████
████████████████████████
██████████▄▄██████████
█████████████████████
███████████████████████
█████████████████████
██████████▀▀██████████
████████████████████████
██████████▄▄████████████
███████████████████████
▀███████████████████████▀
 
 MoBit 
████
██
██
██
██
██
██
██
██
██
██
██
████
 NO   LOGS
 
 LOW  FEES
 
 PGP  GUARANTEE
████
██
██
██
██
██
██
██
██
██
██
██
████
▄██████▄▄▄
█████████████▄▄
███████████████
███████████████
███████████████
███████████████
███░░█████████
███▌▐█████████
█████████████
███████████▀
██████████▀
████████▀
▀██▀▀
Faisal2202
Hero Member
*****
Offline

Activity: 2016
Merit: 604


#kycfree 🗽


View Profile WWW
August 08, 2026, 08:55:58 PM
 #24

Am just fascinated by how AI has quickly become a concern to open source wallets when it is quantum computers that we should have been more scared off. If AI is already doing this, what chance would we stand against quantum computers?
Brother, since the start of 2026, I haven't gone a single day or week without hearing about a hack in the DeFi sector. Bridges, liquidity pools, and other platforms are being exploited by hackers who are finding even the tiniest loopholes in them and then draining as much money as they can. I have read about almost every hack since the start of 2026, and I can tell you for sure that this year could see an all-time high in hacking incidents.

But the last week of July was very calm. I didn't hear about any such incidents during that week, but eventually, I heard about Coldcard, Zeus Wallet, Boltz Swap, then BTCPay Server, and so on. I am sure this month is going to be a crazy month for platforms that still haven't prioritized strengthening their security.

I know what I am going to say is very brutal for those who have lost their funds, but I think this is just one phase. After this phase, AI might become less useful for finding these vulnerabilities. It is like preparing these projects to defend against AI-driven attacks so they can eventually be better prepared for quantum computers.

▄███████████████████████▄
███████████████████████
████████████▀▀██████████
████████████████████████
██████████▄▄██████████
█████████████████████
███████████████████████
█████████████████████
██████████▀▀██████████
████████████████████████
██████████▄▄████████████
███████████████████████
▀███████████████████████▀
 
 MoBit 
████
██
██
██
██
██
██
██
██
██
██
██
████
 NO   LOGS
 
 LOW  FEES
 
 PGP  GUARANTEE
████
██
██
██
██
██
██
██
██
██
██
██
████
▄██████▄▄▄
█████████████▄▄
███████████████
███████████████
███████████████
███████████████
███░░█████████
███▌▐█████████
█████████████
███████████▀
██████████▀
████████▀
▀██▀▀
Pages: « 1 [2]  All
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!