Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
20 commits
Select commit Hold shift + click to select a range
bba83b1
feat(blog): add Ongoing Exploits of Bitcoin Open-Source Software post
dergigi Aug 8, 2026
e7e4f87
feat(blog): fill Ongoing Exploits post body
dergigi Aug 8, 2026
34a27a4
chore(blog): add placeholder image for Ongoing Exploits post
dergigi Aug 8, 2026
8b4651b
chore(blog): shorten Ongoing Exploits summary
dergigi Aug 8, 2026
34121a3
chore(blog): drop open-source from Ongoing Exploits title
dergigi Aug 8, 2026
c401a2d
chore(blog): point official statement to BTCPay X post
dergigi Aug 8, 2026
7a2b344
chore(blog): point vulnerability link to BTCPay X post
dergigi Aug 8, 2026
aca8ef4
chore(blog): link projects we fund to /projects
dergigi Aug 8, 2026
89d291f
chore(blog): point official statement to BTCPay X article
dergigi Aug 8, 2026
7697fde
chore(blog): use xcancel links for BTCPay references
dergigi Aug 8, 2026
b7fe074
feat(blog): show Red Team Fund card on Ongoing Exploits post
dergigi Aug 8, 2026
a010c37
chore(blog): link red team to Code RED post
dergigi Aug 8, 2026
4ef52a2
chore(blog): link donated to Red Team Fund
dergigi Aug 8, 2026
aa2e297
chore(blog): clarify donation infrastructure wording
dergigi Aug 8, 2026
f9732c8
chore(blog): merge OpenSats response into one paragraph
dergigi Aug 8, 2026
a211c4f
chore(blog): clarify remaining donation options
dergigi Aug 8, 2026
4e5be91
chore(blog): link donate to the red fund
dergigi Aug 8, 2026
054fe20
chore(blog): remove redundant donated link
dergigi Aug 8, 2026
ab885ae
feat(blog): add Ongoing Exploits hero image
dergigi Aug 8, 2026
88432fc
feat(blog): replace Ongoing Exploits hero with logo variant
dergigi Aug 8, 2026
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
39 changes: 39 additions & 0 deletions data/blog/ongoing-exploits-of-bitcoin-open-source-software.mdx
Original file line number Diff line number Diff line change
@@ -0,0 +1,39 @@
---
title: 'Ongoing Exploits of Bitcoin Software'
date: '2026-08-08'
tags: ['bitcoin', 'security']
draft: false
authors: ['dergigi', 'default']
images: ['/static/images/blog/112-btcpay-lnd-donations.jpg']
summary: 'A critical BTCPay Server flaw affecting LND is under active exploit.'
fundCard: red
---

In the last 24h multiple critical security vulnerabilities were found and

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

nit, no need to abbreviate here in regular writing

Suggested change
In the last 24h multiple critical security vulnerabilities were found and
In the last 24 hours multiple critical security vulnerabilities were found and

disclosed, most notably a [BTCPay Server vulnerability] that can lead to loss of
funds when using an LND node. Refer to the [official statement] by the BTCPay
Server team for a more detailed description and actionable steps.

OpenSats donation infrastructure was running the affected BTCPay Server and LND
stack. We have reacted immediately and updated our infrastructure shortly after
the vulnerability was announced. No donated funds were lost. As a precautionary
measure we have disabled donations via the lightning network for the time being.
You can still [donate to the red fund] and our other funds using on-chain
transactions or fiat payment rails.

We expect more critical vulnerabilities to be found and patched in the coming
days. Keep an eye out for updates via official channels, not only from the
[projects we fund], but across the whole bitcoin open-source ecosystem.

We would like to thank everyone who has donated to or otherwise supported the
[red team], developers and security researchers who are responsibly disclosing

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

missing "the" here, to align with "and the maintainers"

Suggested change
[red team], developers and security researchers who are responsibly disclosing
[red team], the developers and security researchers who are responsibly disclosing

any issues that are found, and the maintainers who are working around the clock
to make sure that free and open-source software is as secure as it can be.

Thank you.

[BTCPay Server vulnerability]: https://xcancel.com/BtcpayServer/status/2085755643659522240
[official statement]: https://xcancel.com/i/article/2085865561137831938
[donate to the red fund]: /funds/red
[projects we fund]: /projects
[red team]: /blog/code-red-supporting-first-responders
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
Loading