BTCPay Vulnerability Exploited, Users Warned to Update Immediately
BTCPay Server has issued a critical warning to users about a vulnerability that is being actively exploited by attackers. The company recommends updating to version 2.4.2 immediately, or shutting down servers if an update cannot be done right away.
The attack could lead to stolen funds, and users are advised to replace credentials known as macaroons and recreate the macaroons.db file for other Lightning Network backends. Hot on-chain wallets generated in BTCPay should also be moved and recreated.
BTCPay Server credits Bitcoin Red Team members with reporting the vulnerability but has not disclosed how it works, when attacks began, or how many servers were compromised.