BTCPay Server Warns Users of Actively Exploited Critical Flaw

AI مارکیٹ کا خلاصہ
BTCPay Server warned that a critical vulnerability is actively being exploited, potentially enabling unauthorized access and fund loss, including onchain hot wallets generated within BTCPay. The guidance to shut down servers, upgrade immediately, and rotate Lightning "macaroons" credentials highlights acute operational risk for merchants and self-hosted payment infrastructure. Near term, the incident can pressure crypto risk appetite and heighten security-driven caution around Bitcoin payment rails.
اثر کی سطح
● درمیانہ
متاثرہ اثاثے
BTC/USDT+1.17%
AI تجزیاتی سمجھ · BTC/USDTAI تجزیاتی سمجھ
▼ Bearish
ابھی ٹریڈ کریں
⚠️ AI سے تیار کردہ تجزیاتی سمجھ خبروں کے مواد پر مبنی ہے اور صرف معلوماتی مقاصد کے لیے فراہم کی گئی ہے۔ یہ سرمایہ کاری کا مشورہ نہیں ہے اور نہ ہی BingX کے خیالات کی نمائندگی کرتی ہے۔ سرمایہ کاری میں رسک شامل ہے۔ براہ کرم ذمہ داری سے ٹریڈ کریں۔
BTCPay Server has issued an urgent security alert, warning that attackers are actively exploiting a critical vulnerability that could enable unauthorized access and potential loss of funds, according to CoinMarketCap. The project is urging users to upgrade immediately. If a prompt update isn't possible, BTCPay recommends shutting down affected servers until patching can be completed. Users are also advised to rotate credentials without delay. Beyond applying the update, BTCPay says operators should replace Lightning authentication credentials known as macaroons, rebuild the macaroons.db file, and refresh authentication strings used by other Lightning Network backends. For users who previously created an on-chain hot wallet within BTCPay, the team recommends moving funds out immediately and recreating the wallet, indicating the impact may extend beyond backend access to assets managed directly by the server. BTCPay recommends the following steps: shut down the server before attempting to update, apply the update as soon as possible, replace macaroons and rebuild related authentication files, and complete credential rotation. No technical details of the vulnerability have been disclosed. BTCPay credited members of the Bitcoin Red Team with discovering the issue, but did not say how the exploit works, when attacks began, how many servers may be affected, or whether any funds have been stolen. Projects commonly withhold specifics while an exploit is ongoing to avoid enabling additional attacks. For now, BTCPay emphasizes isolation, patching, and credential rotation as the priority. The alert comes amid broader discussion of AI-assisted vulnerability discovery in crypto security. BTCPay did not indicate whether AI tools played a role in this incident. Still, recent cases have highlighted the trend: in May, security researcher Taylor Hornby used Anthropic's Claude Opus to identify a four-year-old vulnerability in Zcash; in August, hardware wallet maker Coinkite said attackers may have used AI to spot firmware weaknesses tied to more than $100 million in stolen bitcoin. On Tuesday, bitcoin exchange service Boltz paused operations after repeated exploits, saying AI-assisted attacks are finding flaws faster than its team can patch them.