BTCPay Server Warns of Active Exploit, Urges Immediate Security Update
BTCPay Server has issued a warning to its users regarding an active exploit that could allow unauthorized access to Bitcoin payment servers and potentially lead to fund theft. The open-source payment processor urged administrators to update their software immediately, specifically installing version 2.4.2 as soon as possible. This comes days after a separate security flaw affecting Coldcard hardware wallets resulted in over $116 million in confirmed losses.
The project did not disclose technical details of the vulnerability to avoid helping attackers, but warned users that if they are unable to update right away, they should turn off their BTCPay Server to prevent unauthorized access. In addition to updating, administrators were advised to refresh macaroon credentials, rotate Lightning Network authentication strings, and move Bitcoin from existing hot wallets into newly created ones.
BTCPay Server credited the Bitcoin Red Team for responsibly disclosing the vulnerability. This incident adds to a series of security breaches that have prompted developers and researchers to strengthen protections for Bitcoin wallets, payment systems, and other critical crypto infrastructure.