AI-generated analysisPublished automatically and not human-verified. Validated context appears in community notes below.
← Watch feed
Critical 86 Bitcoin

Fix: TOTP 2FA bypass via Greenfield Basic auth (#7491)

Public commit record

What the developer wrote

Authored by Nicolas Dorier

75/100 · Adequate
Fix: TOTP 2FA bypass via Greenfield Basic auth (#7491)
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope✓ Links an issue, advisory, or supporting reference✓ Names security-relevant behavior explicitly! No meaningful explanatory body
The short version

What changed, and why it matters

BTCPay Server fixed a bug where accounts protected only by TOTP-based two-factor authentication (2FA) could access the Greenfield API using just an email and password, skipping the second factor. The change now blocks Basic authentication for any account that has any form of 2FA enabled, not just those using FIDO2 security keys. The vendor calls this a critical vulnerability under active exploitation and urges immediate upgrades.

Recommended action

Upgrade to BTCPay Server 2.4.2 or later immediately. If upgrading is not immediately possible, restrict access to the Greenfield API and monitor for unauthorized API access from accounts with TOTP 2FA enabled.

Security signals we found

01

2FA bypass

02

authentication logic flaw

03

TOTP bypass

04

Basic authentication weakness

05

vendor-reported active exploitation

06

critical severity per vendor release notes

Risk score

Why this scored 86/100

Our methodology →
Potential impact 25/30
Exploitability 22/25
Stealth signal 12/15
Affected reach 12/15
Confidence 10/10
Evidence quality 5/5
Primary-source trail

Evidence and disclosure record

Verified links used to place this patch in context. External claims remain attributed to their publishers.

Vendor advisory · Primary

Fix: TOTP 2FA bypass via Greenfield Basic auth

Vendor-authored fix and disclosure explaining that TOTP-only accounts could access the Greenfield API with only an email and password, bypassing the second authentication factor. The report is credited to Ben Carman.

Release notes · Primary

BTCPay Server 2.4.2

Vendor release notes identify this as a critical vulnerability under active exploitation, urge immediate upgrades, and credit Bruno Garcia and Ben Carman through the Bitcoin Red Team effort.

Human-validated context

Community notes

Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.

No validated notes yet.

The AI analysis stands alone for now. Submit a note if you can add evidence or important context.