Bitcoin Forum
August 08, 2026, 10:07:31 AM *
News: COLDCARD users only: critical vulnerability risks funds stored on COLDCARD devices; immediate action required
 
   Home   Help Search Login Register More  
Pages: [1] 2 »  All
  Print  
Author Topic: Critical vulnerability discovered in BTCPay Server  (Read 178 times)
Pmalek (OP)
Legendary
*
Offline

Activity: 3584
Merit: 9432



View Profile
August 07, 2026, 04:50:54 PM
Last edit: Today at 07:00:49 AM by Pmalek
Merited by vapourminer (1), ABCbits (1), Cookdata (1)
 #1

Users of BTCPay Server must know that there is a critical vulnerability in this payment processor right now. It is being exploited by scammers and can lead to the loss of funds.
The developers recommend that all users update to version 2.4.2 as soon as possible. If that's not possible at the moment the alternative is to turn off your BTCPay Server until you can safely upgrade. Spread the word if you know someone that uses BTCPay Server.

My guess is that this is another open-source project that's being targeted with the help of AI.


https://x.com/BtcpayServer/status/2085755643659522240


Update #1:

BTCPay Server thanks the Bitcoin Red Team for discovering and reporting the vulnerability and suggest the following:

Quote
To stay safe, make sure that even after the update, you:
- Completely refresh macaroons and macaroons.db
- Completely refresh auth strings for other LN backends
- If you generated a hot on-chain wallet in BTCPay, you want to move those funds and recreate the wallet
https://x.com/BtcpayServer/status/2085771939008667869

Update #2:

Quote
Our analysis confirms that the attacker used exposed LND .macaroon credentials to access funds. Only LND users are affected, but we recommend everyone update to BTCPay Server 2.4.2.

We found no evidence that on-chain or hot wallets created in BTCPay Server were affected.

Thank you to everyone in the community who sounded the alarm, helped us spread this information quickly, and contacted merchants. Please continue reaching out to BTCPay Server operators you know and ask them to update.

I am deeply sorry to the users who suffered devastating losses. If you were affected or have more questions my DMs are open.
https://x.com/pavlenex/status/2085869178511135043

Security Advisory:
https://x.com/BtcpayServer/status/2085865561137831938

▄▄███████████████████▄▄
▄███████████████████████▄
████████████████████████
█████████████████████████
████████████████████████
████████████▀██████▀████
████████████████████████
█████████▄▄▄▄███████████
██████████▄▄▄████████████
████████████████████████
████████████████▀▀███████
▀███████████████████████▀
▀▀███████████████████▀▀
 
 EARNBET 
| 🏀
 
🏈 🏓
 
🎯 🥊
 
 🎾
 
 🏐
 
🏏 🏎️
|


███████▄▄███████████
████▄██████████████████
██▀▀███████████████▀▀███
▄████████████████████████
▄▄████████▀▀▀▀▀████████▄▄██
███████████████████████████
█████████▌██▀████████████
███████████████████████████
▀▀███████▄▄▄▄▄█████████▀▀██
▀█████████████████████▀██
██▄▄███████████████▄▄███
████▀██████████████████
███████▀▀███████████

....HIGHEST....
VIP REWARDS

  G U A R A N T E E D   
| 
 🜲 
KING OF
THE CASTLE

$200K in prizes
| 
..PLAY NOW..
Swordsoffreedom
Legendary
*
Offline

Activity: 3584
Merit: 1231


Leading Crypto Sports Betting & Casino Platform


View Profile WWW
August 07, 2026, 05:01:19 PM
 #2

My guess is that this is another open-source project that's being targeted with the help of AI.

I don't think it's fair to blame AI for every attack on any open source project.

I haven't seen any evidence so far that this BTCPay Server vulnerability was exploited by AI.

You know, any popular open source software is regularly analyzed by security researcher also by attacker.

When any critical bug is discovered, it's an unfortunate reality that attempt to exploit it before or after a patch is released.

..Stake.com..   ▄████████████████████████████████████▄
   ██ ▄▄▄▄▄▄▄▄▄▄            ▄▄▄▄▄▄▄▄▄▄ ██  ▄████▄
   ██ ▀▀▀▀▀▀▀▀▀▀ ██████████ ▀▀▀▀▀▀▀▀▀▀ ██  ██████
   ██ ██████████ ██      ██ ██████████ ██   ▀██▀
   ██ ██      ██ ██████  ██ ██      ██ ██    ██
   ██ ██████  ██ █████  ███ ██████  ██ ████▄ ██
   ██ █████  ███ ████  ████ █████  ███ ████████
   ██ ████  ████ ██████████ ████  ████ ████▀
   ██ ██████████ ▄▄▄▄▄▄▄▄▄▄ ██████████ ██
   ██            ▀▀▀▀▀▀▀▀▀▀            ██ 
   ▀█████████▀ ▄████████████▄ ▀█████████▀
  ▄▄▄▄▄▄▄▄▄▄▄▄███  ██  ██  ███▄▄▄▄▄▄▄▄▄▄▄▄
 ██████████████████████████████████████████
▄▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▄
█  ▄▀▄             █▀▀█▀▄▄
█  █▀█             █  ▐  ▐▌
█       ▄██▄       █  ▌  █
█     ▄██████▄     █  ▌ ▐▌
█    ██████████    █ ▐  █
█   ▐██████████▌   █ ▐ ▐▌
█    ▀▀██████▀▀    █ ▌ █
█     ▄▄▄██▄▄▄     █ ▌▐▌
█                  █▐ █
█                  █▐▐▌
█                  █▐█
▀▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▀█
▄▄█████████▄▄
▄██▀▀▀▀█████▀▀▀▀██▄
▄█▀       ▐█▌       ▀█▄
██         ▐█▌         ██
████▄     ▄█████▄     ▄████
████████▄███████████▄████████
███▀    █████████████    ▀███
██       ███████████       ██
▀█▄       █████████       ▄█▀
▀█▄    ▄██▀▀▀▀▀▀▀██▄  ▄▄▄█▀
▀███████         ███████▀
▀█████▄       ▄█████▀
▀▀▀███▄▄▄███▀▀▀
..PLAY NOW..
Ambatman
Legendary
*
Offline

Activity: 1092
Merit: 1402


Don't tell anyone


View Profile WWW
August 07, 2026, 05:21:08 PM
Merited by Pmalek (3), vapourminer (1), ABCbits (1)
 #3

And it has begun
I expected this occurring more after the coldcard hack
And I'm assuming developers are also trying to see if there's any bug in their project.
Updating to another version would solve it? Reminds me how people for a brief moment thought the hack didn't affect MK3 upwards.

 

I don't think it's fair to blame AI for every attack on any open source project.
The OP never blamed AI
He only speculated which I support this would have been done with the assistance of AI
With coldcard already showing precedence.

███████████████████████████
███████▄████████████▄██████
████████▄████████▄████████
███▀█████▀▄███▄▀█████▀███
█████▀█▀▄██▀▀▀██▄▀█▀█████
███████▄███████████▄███████
███████████████████████████
███████▀███████████▀███████
████▄██▄▀██▄▄▄██▀▄██▄████
████▄████▄▀███▀▄████▄████
██▄███▀▀█▀██████▀█▀███▄███
██▀█▀████████████████▀█▀███
███████████████████████████
.
.Duelbits PREDICT..
█████████████████████████
█████████████████████████
███████████▀▀░░░░▀▀██████
██████████░░▄████▄░░████
█████████░░████████░░████
█████████░░████████░░████
█████████▄▀██████▀▄████
████████▀▀░░░▀▀▀▀░░▄█████
██████▀░░░░██▄▄▄▄████████
████▀░░░░▄███████████████
█████▄▄█████████████████
█████████████████████████
█████████████████████████
.
.WHERE EVERYTHING IS A MARKET..
█████
██
██







██
██
██████
Will Bitcoin hit $200,000
before January 1st 2027?

    No @1.15         Yes @6.00    
█████
██
██







██
██
██████

  CHECK MORE > 
Iranus
Hero Member
*****
Offline

Activity: 2632
Merit: 626


Leading Crypto Sports Betting & Casino Platform


View Profile
August 07, 2026, 05:46:13 PM
Merited by vapourminer (1)
 #4

afaik, BTCPay Server has also transparently disclosed multiple vulnerabilities in the past and fixed them quickly. This shows that they are not like Coldcard. Rather, they have given more importance to solutions than hiding problems.


github

Look at this, avulnerability related to the 2022 public Point of Sale app was published in the GitHub Advisory Database, and the affected version and patched version are listed.


Since it is open source, any bug is visible to all good people or hackers. Again, for the same reason, the fix is ​​also quickly released to everyone.

..Stake.com..   ▄████████████████████████████████████▄
   ██ ▄▄▄▄▄▄▄▄▄▄            ▄▄▄▄▄▄▄▄▄▄ ██  ▄████▄
   ██ ▀▀▀▀▀▀▀▀▀▀ ██████████ ▀▀▀▀▀▀▀▀▀▀ ██  ██████
   ██ ██████████ ██      ██ ██████████ ██   ▀██▀
   ██ ██      ██ ██████  ██ ██      ██ ██    ██
   ██ ██████  ██ █████  ███ ██████  ██ ████▄ ██
   ██ █████  ███ ████  ████ █████  ███ ████████
   ██ ████  ████ ██████████ ████  ████ ████▀
   ██ ██████████ ▄▄▄▄▄▄▄▄▄▄ ██████████ ██
   ██            ▀▀▀▀▀▀▀▀▀▀            ██ 
   ▀█████████▀ ▄████████████▄ ▀█████████▀
  ▄▄▄▄▄▄▄▄▄▄▄▄███  ██  ██  ███▄▄▄▄▄▄▄▄▄▄▄▄
 ██████████████████████████████████████████
▄▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▄
█  ▄▀▄             █▀▀█▀▄▄
█  █▀█             █  ▐  ▐▌
█       ▄██▄       █  ▌  █
█     ▄██████▄     █  ▌ ▐▌
█    ██████████    █ ▐  █
█   ▐██████████▌   █ ▐ ▐▌
█    ▀▀██████▀▀    █ ▌ █
█     ▄▄▄██▄▄▄     █ ▌▐▌
█                  █▐ █
█                  █▐▐▌
█                  █▐█
▀▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▀█
▄▄█████████▄▄
▄██▀▀▀▀█████▀▀▀▀██▄
▄█▀       ▐█▌       ▀█▄
██         ▐█▌         ██
████▄     ▄█████▄     ▄████
████████▄███████████▄████████
███▀    █████████████    ▀███
██       ███████████       ██
▀█▄       █████████       ▄█▀
▀█▄    ▄██▀▀▀▀▀▀▀██▄  ▄▄▄█▀
▀███████         ███████▀
▀█████▄       ▄█████▀
▀▀▀███▄▄▄███▀▀▀
..PLAY NOW..
Danish Ali
Newbie
*
Online Online

Activity: 12
Merit: 1


View Profile
August 07, 2026, 05:51:12 PM
 #5

This is a good example, because you have more control when you have your own setup, but you have more responsibility as well. While many people choose self-hosted solutions to avoid depending on outside companies, safety updates and upkeep are vital.

The fast response of BTCPay team and the individuals who reported the issue is a good sign. There is no such thing as a perfectly safe software, open source or closed source. It is the way that the community deals with these situations that is important.

These warnings should certainly not be ignored by users, especially in the case of real money. Having control of your own payments is just as important as keeping software updated and following safety practices.
Hamza2424
Legendary
*
Offline

Activity: 1736
Merit: 1156



View Profile WWW
August 07, 2026, 06:03:31 PM
Merited by Pmalek (3)
 #6

My guess is that this is another open-source project that's being targeted with the help of AI.
I don't think it's fair to blame AI for every attack on any open source project.
It is really not fair until it is proven, but ever since AI came out and has continued to improve, especially with models like Claude, which are very advanced and game-changing, hacks have also been increasing.

Of course, no one is talking about this, but this is something that cannot be ignored. Self-testing by these companies has also shown that AI is capable of a lot of things, and it has already been used to find a lot of vulnerabilities. For example, Chinese-sponsored hackers used Claude to break into at least 30 organizations. Claude was also used by a person to find his seed phrase, which was not a hack, but it helped with extortion, real data theft as well. Many hackers have used it to find vulnerabilities in healthcare, emergency services, and other governmental departments to gain access to the people's stored data, which they sell online or use to extort people later.

A hacker used AI to create ransomware that he later sold online to criminals, so with the help of AI, one can solve one problem, which can then help them break into another system, eventually leading to even more serious consequences. That's why I won't disagree with pmalek, as AI is capable of a lot of things. You must have heard they blamed it all on Claude when they bombed the Iranian schoolgirl.

▄▄████████████████████▄▄
▄███████▀▀██████▀▀███████▄
████████████████████████
████████▄▄██████▄▄██████

████████████████████████
██▄▄█████████████▄▄██████
██▀▀██████████████████▄▄██
██████▀▀██████████████▀▀██
██████████████████████████
██████▀▀██████▀▀████████
████████████████████████
▀███████▄▄██████▄▄███████▀
▀▀████████████████████▀▀
 
 DΞX.fo 
▄▄██████
█████████
██████████
█████████
██████████
█████████
▀▀██████

▄███████
▄██████████
████████████
█████████████
█████████████
|
▄▄█
▄████▀
▄███▀
▄██▀▄██
█████▀▀
███████
████████
▀██▄████
▄████▄▄
▄█████▀███
▄█████▀████
█████▀███████
▀██▀█████████
|  BTC     XMR  
  DAI     LTC  
   Fees  0.8%    
Odohu
Hero Member
*****
Online Online

Activity: 1204
Merit: 777



View Profile WWW
August 07, 2026, 06:32:25 PM
 #7

As open source projects are being targeted now, what then is our last line of defense? A lot of people suggested in other posts that using multisig wallets and generating the seed phrase offline and others, but are these methods enough to protect people's money. I really do not feel at ease when I see  with open source system because they were supposed to be rhe safest means of storing Bitcoin.

R


▀▀▀▀▀▀▀██████▄▄
████████████████
▀▀▀▀█████▀▀▀█████
████████▌███▐████
▄▄▄▄█████▄▄▄█████
████████████████
▄▄▄▄▄▄▄██████▀▀
LLBIT|
4,000+ GAMES
███████████████████
██████████▀▄▀▀▀████
████████▀▄▀██░░░███
██████▀▄███▄▀█▄▄▄██
███▀▀▀▀▀▀█▀▀▀▀▀▀███
██░░░░░░░░█░░░░░░██
██▄░░░░░░░█░░░░░▄██
███▄░░░░▄█▄▄▄▄▄████
▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀
█████████
▀████████
░░▀██████
░░░░▀████
░░░░░░███
▄░░░░░███
▀█▄▄▄████
░░▀▀█████
▀▀▀▀▀▀▀▀▀
█████████
░░░▀▀████
██▄▄▀░███
█░░█▄░░██
░████▀▀██
█░░█▀░░██
██▀▀▄░███
░░░▄▄████
▀▀▀▀▀▀▀▀▀
||.
|
▄▄████▄▄
▀█▀
▄▀▀▄▀█▀
▄░░▄█░██░█▄░░▄
█░▄█░▀█▄▄█▀░█▄░█
▀▄░███▄▄▄▄███░▄▀
▀▀█░░░▄▄▄▄░░░█▀▀
░░██████░░█
█░░░░▀▀░░░░█
▀▄▀▄▀▄▀▄▀▄
▄░█████▀▀█████░▄
▄███████░██░███████▄
▀▀██████▄▄██████▀▀
▀▀████████▀▀
.
▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄
░▀▄░▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄░▄▀
███▀▄▀█████████████████▀▄▀
█████▀▄░▄▄▄▄▄███░▄▄▄▄▄▄▀
███████▀▄▀██████░█▄▄▄▄▄▄▄▄
█████████▀▄▄░███▄▄▄▄▄▄░▄▀
███████████░███████▀▄▀
███████████░██▀▄▄▄▄▀
███████████░▀▄▀
████████████▄▀
███████████
▄▄███████▄▄
▄████▀▀▀▀▀▀▀████▄
▄███▀▄▄███████▄▄▀███▄
▄██▀▄█▀▀▀█████▀▀▀█▄▀██▄
▄██▀▄███░░░▀████░███▄▀██▄
███░████░░░░░▀██░████░███
███░████░█▄░░░░▀░████░███
███░████░███▄░░░░████░███
▀██▄▀███░█████▄░░███▀▄██▀
▀██▄▀█▄▄▄██████▄██▀▄██▀
▀███▄▀▀███████▀▀▄███▀
▀████▄▄▄▄▄▄▄████▀
▀▀███████▀▀
OFFICIAL PARTNERSHIP
SOUTHAMPTON FC
FAZE CLAN
SSC NAPOLI
bitmover
Legendary
*
Offline

Activity: 3122
Merit: 7658


Trêvoid █ No KYC-AML Crypto Swaps


View Profile WWW
August 07, 2026, 06:41:51 PM
Merited by vapourminer (1)
 #8

My guess is that this is another open-source project that's being targeted with the help of AI.

I don't think it's fair to blame AI for every attack on any open source project.

I haven't seen any evidence so far that this BTCPay Server vulnerability was exploited by AI.

You know, any popular open source software is regularly analyzed by security researcher also by attacker.

When any critical bug is discovered, it's an unfortunate reality that attempt to exploit it before or after a patch is released.

Every decent developer uses AI now.

Ofc the AI didnt find the vulnerability alone. But the AI enhances the developer/hacker capabilities

So yeah  , AI is to blame for all those attacks to be happening simultaneously or in a small amount of time

▄▄████████████████████▄▄
▄███████▀▀██████▀▀███████▄
████████████████████████
████████▄▄██████▄▄██████

████████████████████████
██▄▄█████████████▄▄██████
██▀▀██████████████████▄▄██
██████▀▀██████████████▀▀██
██████████████████████████
██████▀▀██████▀▀████████
████████████████████████
▀███████▄▄██████▄▄███████▀
▀▀████████████████████▀▀
 
 DΞX.fo 
▄▄██████
█████████
██████████
█████████
██████████
█████████
▀▀██████

▄███████
▄██████████
████████████
█████████████
█████████████
|
▄▄█
▄████▀
▄███▀
▄██▀▄██
█████▀▀
███████
████████
▀██▄████
▄████▄▄
▄█████▀███
▄█████▀████
█████▀███████
▀██▀█████████
|  BTC     XMR  
  DAI     LTC  
   Fees  0.8%    
Swordsoffreedom
Legendary
*
Offline

Activity: 3584
Merit: 1231


Leading Crypto Sports Betting & Casino Platform


View Profile WWW
August 07, 2026, 07:39:05 PM
Merited by vapourminer (1)
 #9

Every decent developer uses AI now.

Ofc the AI didnt find the vulnerability alone. But the AI enhances the developer/hacker capabilities

So yeah  , AI is to blame for all those attacks to be happening simultaneously or in a small amount of time

Attackers have been using automated scanner, fuzzing, static analysis, exploit database, mass scanning and etc since long before AI came along. It is not new for a critical vulnerability to be exposed or patched and many server to be attacked in a short period of time.

So whether AI is creating new threat and whether it is helping existing attacker do the same thing more efficiently, are two different question, imo.

In this case of BTCPay incident, the second explanation seems entirely plausible, yeah. But so far, still we don't have enough evidence to conclude the first.

..Stake.com..   ▄████████████████████████████████████▄
   ██ ▄▄▄▄▄▄▄▄▄▄            ▄▄▄▄▄▄▄▄▄▄ ██  ▄████▄
   ██ ▀▀▀▀▀▀▀▀▀▀ ██████████ ▀▀▀▀▀▀▀▀▀▀ ██  ██████
   ██ ██████████ ██      ██ ██████████ ██   ▀██▀
   ██ ██      ██ ██████  ██ ██      ██ ██    ██
   ██ ██████  ██ █████  ███ ██████  ██ ████▄ ██
   ██ █████  ███ ████  ████ █████  ███ ████████
   ██ ████  ████ ██████████ ████  ████ ████▀
   ██ ██████████ ▄▄▄▄▄▄▄▄▄▄ ██████████ ██
   ██            ▀▀▀▀▀▀▀▀▀▀            ██ 
   ▀█████████▀ ▄████████████▄ ▀█████████▀
  ▄▄▄▄▄▄▄▄▄▄▄▄███  ██  ██  ███▄▄▄▄▄▄▄▄▄▄▄▄
 ██████████████████████████████████████████
▄▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▄
█  ▄▀▄             █▀▀█▀▄▄
█  █▀█             █  ▐  ▐▌
█       ▄██▄       █  ▌  █
█     ▄██████▄     █  ▌ ▐▌
█    ██████████    █ ▐  █
█   ▐██████████▌   █ ▐ ▐▌
█    ▀▀██████▀▀    █ ▌ █
█     ▄▄▄██▄▄▄     █ ▌▐▌
█                  █▐ █
█                  █▐▐▌
█                  █▐█
▀▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▀█
▄▄█████████▄▄
▄██▀▀▀▀█████▀▀▀▀██▄
▄█▀       ▐█▌       ▀█▄
██         ▐█▌         ██
████▄     ▄█████▄     ▄████
████████▄███████████▄████████
███▀    █████████████    ▀███
██       ███████████       ██
▀█▄       █████████       ▄█▀
▀█▄    ▄██▀▀▀▀▀▀▀██▄  ▄▄▄█▀
▀███████         ███████▀
▀█████▄       ▄█████▀
▀▀▀███▄▄▄███▀▀▀
..PLAY NOW..
vapourminer
Legendary
*
Offline

Activity: 5124
Merit: 6645


what is this "brake pedal" you speak of?


View Profile
August 07, 2026, 08:20:30 PM
Merited by Pmalek (3)
 #10

Attackers have been using automated scanner, fuzzing, static analysis, exploit database, mass scanning and etc since long before AI came along. It is not new for a critical vulnerability to be exposed or patched and many server to be attacked in a short period of time.

So whether AI is creating new threat and whether it is helping existing attacker do the same thing more efficiently, are two different question, imo.

every hacker, real or wannabee, now has a genius level assistant with unlimited time and an encyclopedic knowledge of exploits and common errors.. all this "hacker" now needs to do is point it at "crypto" or whatever and wait.

once the low hanging fruit is picked it will get even uglier i fear.

Stalker22
Legendary
*
Offline

Activity: 2324
Merit: 1621



View Profile
August 07, 2026, 09:06:13 PM
Merited by Pmalek (3)
 #11

I don't think it's fair to blame AI for every attack on any open source project.

I haven't seen any evidence so far that this BTCPay Server vulnerability was exploited by AI.

Kimi K3 full open-weight release was on July 27, 2026, just a few days before the ColdCard exploit.  Bitcoin Red Team has already proven that it can be used to find almost 5000 security vulnerabilities (85 of which are critical) across 390 Bitcoin related Open Source projects in just a day.  No one says that the BTCPay Server vulnerability was exploited by AI, but it is very likely that automated AI tools made it dead simple for whoever did this to spot the bug and build an exploit.

█████████████████████████
███████▀▀███████▀▀███████
█████▀░░▄███████▄░░▀█████
███▀░░██████▀░▀████░░▀███
██▀░░▀▀▀████████████░░▀██
██░░█▄████▀▀███▀█████░░██
██░░███▄▄███████▀▀███░░██
██░░████████████████░░██
██▄░░████▄▄██████▄▄█░░▄██
███▄░░██████░░████░░▄███
█████▄░░▀███░░▐▀░░▄█████
███████▄▄███████▄▄███████
█████████████████████████
.
 ROOBET .██████. BET ON WORLD CUP  🗺 ⚽︎.██████.
|

█▄█
▀█▀
████▄▄██████▄▄████
█▄███▀█░░█████░░█▀███▄█
▀█▄▄░▐█████████▌▄▄█▀
██▄▄█████████▄▄████▌
██████▄▄████████
█▀▀████████████████
██████
█████████████
██
█▀▀██████████████
▀▀▀███████████▀▀▀▀
|.
   BET NOW   
taufik123
Legendary
*
artcontest
Online Online

Activity: 3346
Merit: 2437


Duelbits.com


View Profile
August 07, 2026, 09:34:24 PM
Merited by Pmalek (3)
 #12

For some reason now there is more bad news about Bitcoin, starting with the ColdCard hack and now the bad news from BTCPay Server.
People are starting to be wary and now I'm sure all the developers of bitcoin wallet hardware,
mobile wallet app developers and the like might do a thorough check to see if their devices and wallets are safe or if there are some bugs that could be open.

List of updates in v.2.4.2



Faisal2202
Hero Member
*****
Offline

Activity: 2016
Merit: 604


#kycfree 🗽


View Profile WWW
August 07, 2026, 09:50:04 PM
 #13

every hacker, real or wannabee, now has a genius level assistant with unlimited time and an encyclopedic knowledge of exploits and common errors.. all this "hacker" now needs to do is point it at "crypto" or whatever and wait.

once the low hanging fruit is picked it will get even uglier i fear.
I was reading another thread about how Red Team used AI to find thousands of vulnerabilities, some of them being very critical. They also got a lot of help, including some uncensored access to the Kimi K3 model, which might have helped them a lot. But the point is, they used many kinds of AI models to find all those vulnerabilities.

Quote
In 27.5 hours, with almost 10k spent in 24hours, and they have reported 

1 4,962 security findings
2 85 critical vulnerabilities
3 635 high-severity vulnerabilities
https://bitcointalk.org/index.php?topic=5590558.0

The time they took was very short, so they did an amazing job. Sophisticated attacks still require sophisticated attackers. Some people could pick the low-hanging fruit with some of the prompts, but they still need some understanding, because even to use a tool, you need some intelligence.

▄███████████████████████▄
███████████████████████
████████████▀▀██████████
████████████████████████
██████████▄▄██████████
█████████████████████
███████████████████████
█████████████████████
██████████▀▀██████████
████████████████████████
██████████▄▄████████████
███████████████████████
▀███████████████████████▀
 
 MoBit 
████
██
██
██
██
██
██
██
██
██
██
██
████
 NO   LOGS
 
 LOW  FEES
 
 PGP  GUARANTEE
████
██
██
██
██
██
██
██
██
██
██
██
████
▄██████▄▄▄
█████████████▄▄
███████████████
███████████████
███████████████
███████████████
███░░█████████
███▌▐█████████
█████████████
███████████▀
██████████▀
████████▀
▀██▀▀
Alphakilo
Sr. Member
****
Offline

Activity: 1162
Merit: 317


⭐ Razed.com ⭐ The Best Crypto Casino


View Profile
August 07, 2026, 10:02:04 PM
 #14

every hacker, real or wannabee, now has a genius level assistant with unlimited time and an encyclopedic knowledge of exploits and common errors.. all this "hacker" now needs to do is point it at "crypto" or whatever and wait.

once the low hanging fruit is picked it will get even uglier i fear.
I was reading another thread about how Red Team used AI to find thousands of vulnerabilities, some of them being very critical. They also got a lot of help, including some uncensored access to the Kimi K3 model, which might have helped them a lot. But the point is, they used many kinds of AI models to find all those vulnerabilities.

Quote
In 27.5 hours, with almost 10k spent in 24hours, and they have reported 

1 4,962 security findings
2 85 critical vulnerabilities
3 635 high-severity vulnerabilities
https://bitcointalk.org/index.php?topic=5590558.0

The time they took was very short, so they did an amazing job. Sophisticated attacks still require sophisticated attackers. Some people could pick the low-hanging fruit with some of the prompts, but they still need some understanding, because even to use a tool, you need some intelligence.

Am just fascinated by how AI has quickly become a concern to open source wallets when it is quantum computers that we should have been more scared off. If AI is already doing this, what chance would we stand against quantum computers?
Am sure every open source user should not just only upgrade their BTCpay if that's what they are using, but do so to other open source wallets services too, because we don't know how much AI knows at this time but we can anticipate this current threat and ensure counter measures to protect our funds.

RAZED | 100%  
WELCOME
BONUS
█████████████████████
█████████████████████████
████████████▀░░░░▀███████
██████████▀░░▄▀▀▄░░▀█████
██████████▄▄██▄▄██▄░▀████
█████▀░░░░░░░▀██░░█░░████
████░░████▀▀█░░██▀░░▄████
████░░████▄▄█░░█░░▄██████
████░░█▀▀████░░██████████
████░░█▄▄███▀░░██████████
█████▄░░░░░░░▄███████████
█████████████████████████
█████████████████████
█████████████████████
█████████████████████████
██████████▀▀░░░░░▀▀██████
████████▀░░▄▄█░░▀▄░░█████
██████▀░░▄█████▄░░▀░░████
█████░░▄████▄▀░░█▄▄░░████
████░░▄███▄▀░░▄▀██▀░░████
████░░▀▀██░░▄▀███▀░░█████
████░░▄░░▀█████▀░░▄██████
█████░░▀▄░░█▀▀░░▄████████
██████▄▄░░░░░▄▄██████████
█████████████████████████
█████████████████████
|
NO
KYC
██████████████████
 RAZE THE LIMITS   PLAY NOW
██████████████████
suzanne5223
Hero Member
*****
Offline

Activity: 3402
Merit: 751


Want top-notch marketing for your brand, Hire me


View Profile WWW
August 07, 2026, 10:44:24 PM
 #15

every hacker, real or wannabee, now has a genius level assistant with unlimited time and an encyclopedic knowledge of exploits and common errors.. all this "hacker" now needs to do is point it at "crypto" or whatever and wait.

once the low hanging fruit is picked it will get even uglier i fear.
I was reading another thread about how Red Team used AI to find thousands of vulnerabilities, some of them being very critical. They also got a lot of help, including some uncensored access to the Kimi K3 model, which might have helped them a lot. But the point is, they used many kinds of AI models to find all those vulnerabilities.

Quote
In 27.5 hours, with almost 10k spent in 24hours, and they have reported 

1 4,962 security findings
2 85 critical vulnerabilities
3 635 high-severity vulnerabilities
https://bitcointalk.org/index.php?topic=5590558.0

The time they took was very short, so they did an amazing job. Sophisticated attacks still require sophisticated attackers. Some people could pick the low-hanging fruit with some of the prompts, but they still need some understanding, because even to use a tool, you need some intelligence.

Am just fascinated by how AI has quickly become a concern to open source wallets when it is quantum computers that we should have been more scared off. If AI is already doing this, what chance would we stand against quantum computers?
Am sure every open source user should not just only upgrade their BTCpay if that's what they are using, but do so to other open source wallets services too, because we don't know how much AI knows at this time but we can anticipate this current threat and ensure counter measures to protect our funds.
You don't need to be surprised; ever since CEX started using AI to detect fraud and illicit transactions months ago, I believe that should give us a footprint about some of the things that AI will be used for in the future.
About quantum computers, there's no need to be scared of QC if you're using a 256bits entropy wallet and your wallet public key is not exposed.
As for BTCpay, the team seems to always attend to issues asap so their service user will need to wait for their update on what to do after the issue is fixed, so we can't tell anything now.

▄▄███████████████████▄▄
▄███████████████████████▄
███████████████████████
████████▀▀▀▀██▀█▄▀███████
███▀▀██▄▄██▄██▌▄▄▄▄▄██
████▄█████▐██▀▄█▀▀█████
█████▌██▀▀▄█▀██▄██▄███
██▄▄▄▄███████████▐███████
████████▐█████████▀▀█████
███████▄██████▀█▄▄▄▄▄████
███████████████████████

▀███████████████████████▀
▀▀███████████████████▀▀

 Kings Game  
 
 🎰   🎲   ⚽ 
████
██
██
██
██
██
██
██
██
██
██
██
████
████████████████████████████


RAKEBACK
..UP TO 30%..
████████████████████████████
████
██
██
██
██
██
██
██
██
██
██
██
████
████
██
██
██
██
██
██
██
██
██
██
██
████
████████████████████████████
 
..500%..
WELCOME BONUS
+ 250 FREE SPINS
████████████████████████████
████
██
██
██
██
██
██
██
██
██
██
██
████

   WIN NOW     
ABCbits
Legendary
*
Offline

Activity: 3696
Merit: 10273



View Profile
Today at 06:45:05 AM
 #16

Update:

BTCPay Server thanks the Bitcoin Red Team for discovering and reporting the vulnerability and suggest the following:

Quote
To stay safe, make sure that even after the update, you:
- Completely refresh macaroons and macaroons.db
- Completely refresh auth strings for other LN backends
- If you generated a hot on-chain wallet in BTCPay, you want to move those funds and recreate the wallet
https://x.com/BtcpayServer/status/2085771939008667869

It's good to see they acknowledged Bitcoin Red Team, it seems i was worried too much about the team finding.


I really do not feel at ease when I see  with open source system because they were supposed to be rhe safest means of storing Bitcoin.

People who claim open-source wallet as safest probably generalize too much. I mostly agree with such statement only when such wallet is popular and have been around for some time. Even considering recent known vulnerability on open-source/source-code available wallet, IMO using closed source wallet isn't good alternative either, unless you deeply trust whoever create and maintain it.

Pmalek (OP)
Legendary
*
Offline

Activity: 3584
Merit: 9432



View Profile
Today at 06:59:46 AM
 #17

Update:

Quote
Our analysis confirms that the attacker used exposed LND .macaroon credentials to access funds. Only LND users are affected, but we recommend everyone update to BTCPay Server 2.4.2.

We found no evidence that on-chain or hot wallets created in BTCPay Server were affected.

Thank you to everyone in the community who sounded the alarm, helped us spread this information quickly, and contacted merchants. Please continue reaching out to BTCPay Server operators you know and ask them to update.

I am deeply sorry to the users who suffered devastating losses. If you were affected or have more questions my DMs are open.
https://x.com/pavlenex/status/2085869178511135043

Security Advisory:
https://x.com/BtcpayServer/status/2085865561137831938


I don't think it's fair to blame AI for every attack on any open source project.
I didn't blame AI. I said that AI was most probably used to target and find vulnerabilities in many open-source projects. BTCPay Server being one of them. The blame is on the people making prompts and using AIs for such purposes. At the same time, other groups, like the Bitcoin Red Team, use AI capabilities to find the same vulnerabilities, not to abuse them but to report findings to developers to help patch them up. AI is just a tool. People decide what to do with it.

I haven't seen any evidence so far that this BTCPay Server vulnerability was exploited by AI.
I doubt you will, but I am pretty sure it was done with AI. After the Coldcard hack, we have had multiple projects announcing disruptions or shutdowns of service and all that is happening in a shot space of time. That tells you that there is something new on the market, making it easier to find exploits and bugs.

▄▄███████████████████▄▄
▄███████████████████████▄
████████████████████████
█████████████████████████
████████████████████████
████████████▀██████▀████
████████████████████████
█████████▄▄▄▄███████████
██████████▄▄▄████████████
████████████████████████
████████████████▀▀███████
▀███████████████████████▀
▀▀███████████████████▀▀
 
 EARNBET 
| 🏀
 
🏈 🏓
 
🎯 🥊
 
 🎾
 
 🏐
 
🏏 🏎️
|


███████▄▄███████████
████▄██████████████████
██▀▀███████████████▀▀███
▄████████████████████████
▄▄████████▀▀▀▀▀████████▄▄██
███████████████████████████
█████████▌██▀████████████
███████████████████████████
▀▀███████▄▄▄▄▄█████████▀▀██
▀█████████████████████▀██
██▄▄███████████████▄▄███
████▀██████████████████
███████▀▀███████████

....HIGHEST....
VIP REWARDS

  G U A R A N T E E D   
| 
 🜲 
KING OF
THE CASTLE

$200K in prizes
| 
..PLAY NOW..
NotATether
Legendary
*
Offline

Activity: 2422
Merit: 10111


┻┻ ︵㇏(°□°㇏)


View Profile WWW
Today at 07:49:21 AM
 #18

Cheers, my Saturday morning is ruined now.

As open source projects are being targeted now, what then is our last line of defense? A lot of people suggested in other posts that using multisig wallets and generating the seed phrase offline and others, but are these methods enough to protect people's money. I really do not feel at ease when I see  with open source system because they were supposed to be rhe safest means of storing Bitcoin.

They are not targeting open source projects, they are a team of researchers searching for bugs in all open source software and reporting them to the maintainers, ever since the Coldcard hack.

Thousands of dollars in credits are spent per day in order to find these security flaws.

 
 b1exch.to 
  ETH      DAI   
  BTC      LTC   
  USDT     XMR    
.███████████▄▀▄▀
█████████▄█▄▀
███████████
███████▄█▀
█▀█
▄▄▀░░██▄▄
▄▀██▄▀█████▄
██▄▀░▄██████
███████░█████
█░████░█████████
█░█░█░████░█████
█░█░█░██░█████
▀▀▀▄█▄████▀▀▀
YellowSwap
Full Member
***
Online Online

Activity: 644
Merit: 198



View Profile
Today at 07:59:04 AM
 #19

The ColdCard case could be the beginning of something good and so far it's looking like it, maybe from now on the main focus will be 100% on the vulnerabilities on the Blockchain system.

It's a painful incident but it's also for the greater good, although I keep wishing that ColdCard takes the effort to pay all affected people back but we need to make sure that this will never happen again.

If bad actors can use AI to find breaches and vulnerabilities it's highly time that Devs and the good actors who want the best for this crypto space to start using AI too, if they find it first they can fix it first

Die_empty
Legendary
*
Offline

Activity: 1526
Merit: 1333


Give all before death


View Profile
Today at 08:16:07 AM
 #20

BTCPay Server thanks the Bitcoin Red Team for discovering and reporting the vulnerability and suggest the following:
In this thread What's your take on this moment?, we discussed Bitcoin Red Team. Some members didn't see anything special about how they selflessly reviewed many core Bitcoin projects after the Coldcard problem. But I am happy to see that their discovery and report have helped BTCPay Server avoid what would have been another disaster. 

I haven't seen any evidence so far that this BTCPay Server vulnerability was exploited by AI.
I doubt you will, but I am pretty sure it was done with AI. After the Coldcard hack, we have had multiple projects announcing disruptions or shutdowns of service and all that is happening in a shot space of time. That tells you that there is something new on the market, making it easier to find exploits and bugs.
With the rate at which AI is discovering flaws in crypto projects recently, it is not wrong to assume that AI is involved in this one. Anthropic's Claude Opus 4.8 was used to find a four-year-old Zcash vulnerability that could have allowed attackers to create unlimited counterfeit ZEC. It was announced that the Coldcard attackers used AI to find a firmware flaw, and Boltz suspended its service after they discovered that AI-assisted attacks were finding vulnerabilities faster than its team could address them.


https://tech.yahoo.com/cybersecurity/articles/bitcoin-payment-btcpay-warns-critical-200034427.html

▄▄███████████████████▄▄
▄███████████████████████▄
████████████████████████
█████████████████████████
████████████████████████
████████████▀██████▀████
████████████████████████
█████████▄▄▄▄███████████
██████████▄▄▄████████████
████████████████████████
████████████████▀▀███████
▀███████████████████████▀
▀▀███████████████████▀▀
 
 EARNBET 
| 🏀
 
🏈 🏓
 
🎯 🥊
 
 🎾
 
 🏐
 
🏏 🏎️
|


███████▄▄███████████
████▄██████████████████
██▀▀███████████████▀▀███
▄████████████████████████
▄▄████████▀▀▀▀▀████████▄▄██
███████████████████████████
█████████▌██▀████████████
███████████████████████████
▀▀███████▄▄▄▄▄█████████▀▀██
▀█████████████████████▀██
██▄▄███████████████▄▄███
████▀██████████████████
███████▀▀███████████

....HIGHEST....
VIP REWARDS

  G U A R A N T E E D  
| 
 🜲 
KING OF
THE CASTLE

$200K in prizes
| 
..PLAY NOW..
Pages: [1] 2 »  All
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!