Key Highlights
- BTCPay Server confirmed a critical vulnerability is being actively exploited.
- The project urged users to immediately upgrade to version 2.4.2.
- Operators unable to patch immediately were advised to shut down servers until they can update.
BTCPay Server has issued an urgent security advisory after confirming that attackers are actively exploiting a critical vulnerability that could allow unauthorized access to their Bitcoin payment servers which could potentially lead to loss of funds.
In a notice published on August 7, the open-source Bitcoin payment processor urged administrators to immediately update their installations to BTCPay Server version 2.4.2, warning that systems running older versions remain exposed.
The project instructed users to install the latest release through the server maintenance panel and verify that the footer displays version 2.4.2 after the update.
Operators told to shut servers down if they cannot patch
For operators unable to install the update immediately, BTCPay Server recommended temporarily shutting down affected servers until the security patch can be applied.
“If you are unable to update right away, turn off your BTCPay Server to prevent unauthorized access until you can update.”
The team did not disclose technical details of the vulnerability, a common practice when exploits are already active to avoid providing attackers with additional information before users have had an opportunity to patch their systems.
Users told to rotate credentials and move funds
BTCPay Server also advised administrators to perform additional security steps after upgrading.
According to the project, users should:
- Refresh all macaroon files and the macaroon.db database.
- Rotate authentication strings used with Lightning Network backends.
- Move Bitcoin from any hot on-chain wallets created within BTCPay Server and generate new wallets afterward.
These measures are intended to invalidate potentially compromised credentials and reduce the risk of attackers maintaining access after the software update.
Responsible disclosure led to patch
The project credited members of the Bitcoin Red Team for privately reporting the vulnerability through a responsible disclosure process.
BTCPay Server thanked security researchers including Rob Hamilton, Craig Raw, Calle, and Evan Kaloudis for helping identify and address the issue before broader technical details were released.
The company has not disclosed how many installations may have been affected or whether confirmed thefts have occurred.
Security alerts often become opportunities for scammers
The warning also serves as a reminder that attackers frequently exploit high-profile security incidents to launch secondary phishing campaigns.
Earlier this week, European watchdogs warned that fraudsters were impersonating both regulators and cryptocurrency exchanges during the European Union’s MiCA transition period, convincing users to move digital assets to fraudulent wallets under the guise of regulatory compliance.
Security researchers have repeatedly cautioned that fake software updates, fraudulent support messages, and phishing emails often appear shortly after major vulnerabilities become public.
Given the latest BTCPay Server exploit, users are being encouraged to download updates only from official sources and verify all communications before taking action.
Self-custody requires active security management
The incident highlights one of the trade-offs of self-hosted Bitcoin infrastructure.
While platforms like BTCPay Server allow merchants and businesses to process Bitcoin payments without relying on third-party custodians, users are responsible for maintaining software updates and securing their own infrastructure.
For operators running self-hosted crypto services, applying security patches promptly remains one of the most effective defenses against active exploitation.
Also Read: Russian FSB Targets Nine Alleged Crypto Laundering Operations
