Join Nostr
2026-08-08 21:57:41 UTC
in reply to

Dr. Hax on Nostr: According to the official changelog, it was just a 2FA bug. No risk of loss of funds ...

According to the official changelog, it was just a 2FA bug. No risk of loss of funds if you have a strong password.

Having said that, BTCPay did the right thing by labeling it as a vulnerability, and I'd rather have them inflate its severity than try to downplay it. I wouldn't call it "critical", but I have no qualms about our difference of opinion.

Besides, there are probably some people out there who are using admin/password1 and were only not pwned because they had 2FA enabled. For them, yeah, it's critical.