BTCPay Server urges immediate update after active exploit that can steal funds BTCPay Server on Aug. 7 warned users to install version 2.4.2 immediately after discovering a critical vulnerability that is being actively exploited and “can result in the loss of funds,” the project said via its official X account. What operators must do now - Update immediately using the server’s built-in maintenance interface: Admin Dashboard → Server → Maintenance → Update. - Confirm the server footer shows version 2.4.2. - If you cannot apply the patch right away, shut down your BTCPay Server until you can install the fixed release. The project explicitly recommends taking affected servers offline to block further unauthorized access. What is known—and what isn’t - BTCPay Server has labeled the flaw critical and confirmed active exploitation. - The team has not disclosed which older versions are vulnerable, how attackers gain access, how many instances were compromised, or whether any funds have been lost. - No indicators of compromise or technical details have been published yet, so operators may have limited means to determine if they were targeted. Why this matters BTCPay Server is an open-source, self-hosted payment processor that lets merchants accept Bitcoin and Lightning payments on infrastructure they control. That non-custodial model reduces reliance on third parties, but it also means individual operators are responsible for updates and security. A compromised installation can expose payment operations or other sensitive server functions depending on the flaw. Broader context The disclosure follows a recent security incident at Zeus Wallet, which temporarily took systems offline after a cyberattack; Zeus reported no customer funds lost and said its probe found no Lightning node software vulnerability. There’s currently no evidence linking the two incidents. Security reviews across the Bitcoin ecosystem have intensified: the volunteer Bitcoin Red Team recently flagged nearly 5,000 potential issues across 390 projects, with 720 findings rated high or critical. Bottom line Treat this as an emergency security action, not routine maintenance: update to v2.4.2 through the server’s official interface or power down the server until you can. Operators should also review server activity for signs of unauthorized access, knowing that formal indicators of compromise have not yet been provided. More technical details may arrive once a critical mass of users are patched and public disclosure no longer increases risk to unpatched systems. Read more AI-generated news on: undefined/news