-
-
Notifications
You must be signed in to change notification settings - Fork 39
Blog post: Ongoing Exploits of Bitcoin Software #910
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Merged
+39
−0
Merged
Changes from all commits
Commits
Show all changes
20 commits
Select commit
Hold shift + click to select a range
bba83b1
feat(blog): add Ongoing Exploits of Bitcoin Open-Source Software post
dergigi e7e4f87
feat(blog): fill Ongoing Exploits post body
dergigi 34a27a4
chore(blog): add placeholder image for Ongoing Exploits post
dergigi 8b4651b
chore(blog): shorten Ongoing Exploits summary
dergigi 34121a3
chore(blog): drop open-source from Ongoing Exploits title
dergigi c401a2d
chore(blog): point official statement to BTCPay X post
dergigi 7a2b344
chore(blog): point vulnerability link to BTCPay X post
dergigi aca8ef4
chore(blog): link projects we fund to /projects
dergigi 89d291f
chore(blog): point official statement to BTCPay X article
dergigi 7697fde
chore(blog): use xcancel links for BTCPay references
dergigi b7fe074
feat(blog): show Red Team Fund card on Ongoing Exploits post
dergigi a010c37
chore(blog): link red team to Code RED post
dergigi 4ef52a2
chore(blog): link donated to Red Team Fund
dergigi aa2e297
chore(blog): clarify donation infrastructure wording
dergigi f9732c8
chore(blog): merge OpenSats response into one paragraph
dergigi a211c4f
chore(blog): clarify remaining donation options
dergigi 4e5be91
chore(blog): link donate to the red fund
dergigi 054fe20
chore(blog): remove redundant donated link
dergigi ab885ae
feat(blog): add Ongoing Exploits hero image
dergigi 88432fc
feat(blog): replace Ongoing Exploits hero with logo variant
dergigi File filter
Filter by extension
Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
There are no files selected for viewing
39 changes: 39 additions & 0 deletions
39
data/blog/ongoing-exploits-of-bitcoin-open-source-software.mdx
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change | ||||
|---|---|---|---|---|---|---|
| @@ -0,0 +1,39 @@ | ||||||
| --- | ||||||
| title: 'Ongoing Exploits of Bitcoin Software' | ||||||
| date: '2026-08-08' | ||||||
| tags: ['bitcoin', 'security'] | ||||||
| draft: false | ||||||
| authors: ['dergigi', 'default'] | ||||||
| images: ['/static/images/blog/112-btcpay-lnd-donations.jpg'] | ||||||
| summary: 'A critical BTCPay Server flaw affecting LND is under active exploit.' | ||||||
| fundCard: red | ||||||
| --- | ||||||
|
|
||||||
| In the last 24h multiple critical security vulnerabilities were found and | ||||||
| disclosed, most notably a [BTCPay Server vulnerability] that can lead to loss of | ||||||
| funds when using an LND node. Refer to the [official statement] by the BTCPay | ||||||
| Server team for a more detailed description and actionable steps. | ||||||
|
|
||||||
| OpenSats donation infrastructure was running the affected BTCPay Server and LND | ||||||
| stack. We have reacted immediately and updated our infrastructure shortly after | ||||||
| the vulnerability was announced. No donated funds were lost. As a precautionary | ||||||
| measure we have disabled donations via the lightning network for the time being. | ||||||
| You can still [donate to the red fund] and our other funds using on-chain | ||||||
| transactions or fiat payment rails. | ||||||
|
|
||||||
| We expect more critical vulnerabilities to be found and patched in the coming | ||||||
| days. Keep an eye out for updates via official channels, not only from the | ||||||
| [projects we fund], but across the whole bitcoin open-source ecosystem. | ||||||
|
|
||||||
| We would like to thank everyone who has donated to or otherwise supported the | ||||||
| [red team], developers and security researchers who are responsibly disclosing | ||||||
|
Contributor
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. missing "the" here, to align with "and the maintainers"
Suggested change
|
||||||
| any issues that are found, and the maintainers who are working around the clock | ||||||
| to make sure that free and open-source software is as secure as it can be. | ||||||
|
|
||||||
| Thank you. | ||||||
|
|
||||||
| [BTCPay Server vulnerability]: https://xcancel.com/BtcpayServer/status/2085755643659522240 | ||||||
| [official statement]: https://xcancel.com/i/article/2085865561137831938 | ||||||
| [donate to the red fund]: /funds/red | ||||||
| [projects we fund]: /projects | ||||||
| [red team]: /blog/code-red-supporting-first-responders | ||||||
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
Oops, something went wrong.
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
nit, no need to abbreviate here in regular writing