- Published on
Ongoing Exploits of Bitcoin Software
- Authors

- Name
- Gigi
- @dergigi

- Name
- OpenSats
In the last 24h multiple critical security vulnerabilities were found and disclosed, most notably a BTCPay Server vulnerability that can lead to loss of funds when using an LND node. Refer to the official statement by the BTCPay Server team for a more detailed description and actionable steps.
OpenSats donation infrastructure was running the affected BTCPay Server and LND stack. We have reacted immediately and updated our infrastructure shortly after the vulnerability was announced. No donated funds were lost. As a precautionary measure we have disabled donations via the lightning network for the time being. You can still donate to the red fund and our other funds using on-chain transactions or fiat payment rails.
We expect more critical vulnerabilities to be found and patched in the coming days. Keep an eye out for updates via official channels, not only from the projects we fund, but across the whole bitcoin open-source ecosystem.
We would like to thank everyone who has donated to or otherwise supported the red team, developers and security researchers who are responsibly disclosing any issues that are found, and the maintainers who are working around the clock to make sure that free and open-source software is as secure as it can be.
Thank you.