Bitcoin Payment Service BTCPay Warns Critical Flaw Is Under Active Attack
Summary
BTCPay Server warned that attackers are actively exploiting a critical vulnerability that could lead to stolen funds. Users were told to upgrade immediately to version 2.4.2 and verify the update in the server footer. If upgrading right away isn’t possible, the server should be turned off to block unauthorized access. The project also advised rotating sensitive credentials, recreating macaroons.db, refreshing authentication strings for Lightning backends, and moving funds from any hot on-chain wallet before recreating it. The flaw was reported by Bitcoin Red Team members. BTCPay Server has not disclosed how the bug works, when exploitation started, how many servers were affected, or whether funds were actually stolen.
