BTCPay Server Flags Critical Vulnerability Under Active Exploitation, Tells Admins to Upgrade

AI مارکیٹ کا خلاصہ
BTCPay Server disclosed a critical vulnerability under active exploitation that could enable unauthorized access and potential fund losses, urging immediate upgrades or shutdowns plus credential rotation and wallet migration. While impact is localized to merchants and self-hosted payment processors, the event raises near-term operational and security risk across Bitcoin commerce and Lightning-linked backends. Lack of disclosed scope or confirmed losses adds uncertainty and can dampen sentiment.
اثر کی سطح
● درمیانہ
متاثرہ اثاثے
BTC/USDT+1.17%
AI تجزیاتی سمجھ · BTC/USDTAI تجزیاتی سمجھ
▼ Bearish
ابھی ٹریڈ کریں
⚠️ AI سے تیار کردہ تجزیاتی سمجھ خبروں کے مواد پر مبنی ہے اور صرف معلوماتی مقاصد کے لیے فراہم کی گئی ہے۔ یہ سرمایہ کاری کا مشورہ نہیں ہے اور نہ ہی BingX کے خیالات کی نمائندگی کرتی ہے۔ سرمایہ کاری میں رسک شامل ہے۔ براہ کرم ذمہ داری سے ٹریڈ کریں۔
BTCPay Server said on X on Aug. 8 that it has identified a critical vulnerability in its Bitcoin payment processing platform that is currently being actively exploited, potentially enabling unauthorized access and leading to losses of funds, according to ChainThink. The project is instructing administrators to upgrade to version 2.4.2 and verify the update is complete by checking the server footer. If an immediate upgrade is not possible, BTCPay Server recommends temporarily shutting down the service to reduce exposure. BTCPay Server also advised users to rotate potentially exposed macaroon credentials, rebuild the macaroons.db file, and refresh authentication strings for other Lightning Network backends. For users running a hot wallet created within BTCPay Server, the guidance is to move funds out and recreate the wallet. BTCPay Server has not disclosed technical details of the flaw, when the attacks began, how many servers are affected, or whether any funds have been stolen. The issue was reported by a member of the Bitcoin Red Team.