BTCPay warns of actively exploited vulnerability that could drain funds
Quick TakeMakers of the free, open-source bitcoin payment processor BTCPay urged users to update their servers as a critical vulnerability is “being actively exploited.” BTCPay Server disclosed that a critical vulnerability is “being actively exploited” on Friday and urged users to update their servers to version 2.4.2, according to its official X account. While the team said funds may be at risk, it is unclear how many users have been exploited or how much has been lost, if any. “If you are unable to update right away, turn off your BTCPay Server to prevent unauthorized access until you can update,” BTC Pay said. Details surrounding the attack are also currently limited. The Block reached out to BTCPay Server for comment. BTCPay Server is a free, open-source, self-hosted bitcoin payment processor that lets individuals and businesses accept bitcoin and Lightning payments directly with no fees or intermediaries. Launched as an alternative to BitPay, it has gained particular affection among Bitcoin maximalists. The vulnerability comes on the heels of the Coldcard exploit affecting a popular brand of Bitcoin-only wallets that has led to at least $116 million in confirmed losses so far. This article is breaking and may be updated as The Block learns more. Disclaimer: The Block is an