Crypto

BTCPay Server warns active exploit may drain funds



BTCPay Server has urged users to install version 2.4.2 immediately after discovering that attackers are actively exploiting a critical vulnerability that could lead to stolen funds.

Summary

  • BTCPay Server v2.4.2 contains the required security update.
  • The vulnerability is already being actively exploited, according to the project.
  • Operators unable to update should shut down their servers immediately.
  • BTCPay Server has not disclosed the attack method or total financial losses.

BTCPay Server tells users to install v2.4.2

BTCPay Server issued the warning through its official X account on Aug. 7, describing the vulnerability as critical and saying successful exploitation could result in the loss of funds.

The project instructed server administrators to open the Admin Dashboard and navigate to Server, Maintenance and Update. Operators should then confirm that the version number displayed in the server footer reads 2.4.2.

“There is a critical vulnerability being actively exploited on BTCPay Server, which can result in the loss of funds,” the project said.

Users who cannot complete the update immediately have been told to turn off their BTCPay Server until the patched version can be installed. The measure is intended to block further unauthorized access to servers that may remain exposed.

BTCPay Server did not identify which previous versions are vulnerable. It also did not disclose how attackers are gaining access, how many servers have been compromised, or whether any losses have been confirmed.

Critical flaw threatens self-hosted Bitcoin payments

BTCPay Server is an open-source payment processor that lets merchants accept Bitcoin and Lightning Network payments through infrastructure they control. Unlike custodial payment platforms, operators are responsible for maintaining and securing their own installations.

That structure reduces reliance on a centralized payment provider but places the responsibility for software updates on individual merchants and server administrators. A compromised installation could expose payment operations or other sensitive server functions, depending on the vulnerability’s reach.

The project’s recommendation to shut down systems shows the urgency of the threat. Operators should not leave an affected server online while waiting for a convenient maintenance period because BTCPay Server has confirmed that exploitation is already occurring.

Users should obtain the update through the server’s official maintenance interface and verify the 2.4.2 version string. The project has not advised users to rely on third-party downloads or unofficial fixes.

Bitcoin infrastructure faces wider security review

The disclosure follows another recent incident involving Bitcoin payment infrastructure. As reported by crypto.news, Zeus Wallet took its infrastructure offline after containing a cyberattack and began auditing its systems before restoring services.

Zeus said no customer funds were lost or placed at risk. It also said its investigation had not identified a vulnerability in Lightning node software. No evidence currently indicates that the Zeus incident and the BTCPay Server vulnerability are connected.

Security reviews have expanded across the Bitcoin ecosystem following a series of recent attacks. Crypto.news reported on Aug. 6 that the volunteer Bitcoin Red Team had found 4,962 potential issues while reviewing 390 Bitcoin-related projects.

The group classified 720 of those findings as high or critical severity. Its work covers Bitcoin wallets, cryptographic libraries and infrastructure software, although it did not publicly identify projects with unresolved critical flaws.

What BTCPay Server operators should do next

BTCPay Server operators should treat the upgrade as an emergency security action rather than a routine software update. Servers should remain offline if administrators cannot confirm that version 2.4.2 has been installed.

Merchants may also need to review server activity for signs of unauthorized access. However, BTCPay Server has not yet published indicators of compromise or technical details that operators could use to determine whether their systems were targeted.

Further information may follow once more users have installed the patch and public disclosure no longer increases the risk to unpatched servers. Until then, the project’s guidance remains limited but direct: update to v2.4.2 or shut down the server.



Source link

LEAVE A RESPONSE

Your email address will not be published. Required fields are marked *