BTCPay Server releases emergency fix for actively exploited flaw
AI Market Summary
BTCPay Server disclosed and patched a critical vulnerability under active exploitation that could enable unauthorized access and fund losses, urging immediate upgrades and temporary shutdowns if unpatched. Required post-update steps (rotating macaroons/credentials and migrating hot-wallet funds) highlight elevated operational risk for self-hosted Bitcoin payment infrastructure. Near term, this can pressure crypto payment adoption sentiment and raise perceived custodial/security risk around BTC transaction rails.
Impact level
● Medium
Affected assets
BTC/USDT+0.80%
AI Insight · BTC/USDTAI Insight
▼ Bearish
Trade now
⚠️ AI-generated insights are based on news content and are provided for informational purposes only. They do not constitute investment advice or represent the views of BingX. Investing involves risk. Please trade responsibly.
BTCPay Server (@BtcpayServer) has issued an urgent security alert over a critical vulnerability that is being actively exploited and could lead to loss of funds. The project is urging all operators to upgrade to version 2.4.2 immediately. Those unable to update right away are advised to shut down their BTCPay Server temporarily to prevent unauthorized access.
The issue was reported by the Bitcoin Red Team. Integrators are also advised to upgrade NBXplorer to version 2.6.10.
BTCPay Server said updating is only the first step. After applying the fix, operators should rotate macaroons and backend authentication credentials. The team also recommends moving funds out of any hot wallet created within BTCPay before recreating that wallet.
The number of affected servers and the size of potential losses have not been disclosed.