BTCPay Server Vulnerability Exposes Funds to Thieves
BTCPay Server has issued an urgent warning to its users about a critical vulnerability in their system, which could result in stolen funds. The project urges operators to install version 2.4.2 immediately, as attackers are actively exploiting the flaw.
The vulnerability affects all previous versions of BTCPay Server and can be identified by confirming that the server footer displays version 2.4.2 after updating. Users who cannot complete the update should shut down their servers to prevent further unauthorized access.
BTCPay Server has not disclosed the method of attack or any confirmed losses, but advises users to treat this as an emergency security action rather than a routine software update.