Key facts
- BTCPay Server is warning users about a critical vulnerability being actively exploited by attackers.
- Administrators are instructed to update to version 2.4.2 immediately or shut down their servers.
- Users should also replace credentials, recreate macaroons.db files, and refresh authentication strings.
- Funds in hot on-chain wallets generated within BTCPay should be moved.
- The vulnerability was reported by members of the Bitcoin Red Team.
BTCPay Server issued an urgent alert on Friday, stating that attackers are actively exploiting a critical vulnerability within its platform. The Bitcoin payment processor strongly advised administrators to immediately update to version 2.4.2 or, if unable to do so, to shut down their servers to prevent unauthorized access and potential theft of funds. The company also recommended replacing credentials, recreating the macaroons.db file, and refreshing authentication strings for Lightning Network backends. Users who generated hot on-chain wallets within BTCPay were urged to move those funds and recreate the wallet. The vulnerability was reported by members of the Bitcoin Red Team. BTCPay Server has not yet disclosed specific details about the flaw, the timeline of the attacks, the number of compromised servers, or whether any funds have been stolen. This incident occurs amid a growing trend of vulnerabilities in crypto projects being discovered or exploited with the assistance of artificial intelligence.
