BTCPay Server has told users to install version 2.4.2 immediately after discovering a critical vulnerability that the project says is already being exploited in the wild. According to the warning, successful attacks could result in the loss of funds.

The project said operators who cannot apply the patch right away should shut down their BTCPay Server instances until the update is installed. It has not yet disclosed which earlier versions are affected, how the attacks work, or whether any thefts have been confirmed.

Emergency warning issued on Aug. 7

BTCPay Server published the alert through its official X account on Aug. 7 and described the issue as a critical vulnerability. The project said the fix is included in version 2.4.2 and instructed administrators to treat the release as an urgent security update rather than routine maintenance.

To check the installation, operators were told to open the Admin Dashboard, go to Server, then Maintenance and Update, and verify that the version shown in the server footer is 2.4.2. The guidance was direct: if the update cannot be completed immediately, the server should be turned off.

Why the risk is significant

BTCPay Server is an open-source payment processor used to accept Bitcoin and Lightning Network payments on self-managed infrastructure. That model reduces dependence on a centralized payments provider, but it also means merchants and administrators are responsible for keeping their own systems patched and secure.

Because the software is self-hosted, a serious flaw can affect not only payment flows but potentially other sensitive server functions, depending on the scope of the vulnerability. BTCPay Server’s advice to take systems offline if they cannot be updated underscores how urgent the project considers the threat.

What remains unknown

The project has so far withheld several key technical details. It has not said which past versions are vulnerable, how attackers are gaining access, how many servers may have been compromised, or whether any financial losses have already occurred.

BTCPay Server also has not published indicators of compromise or other forensic guidance that operators could use to determine whether their systems were targeted. For now, the project has pointed users only to the official maintenance interface and has not advised relying on third-party downloads or unofficial fixes.

Broader pressure on Bitcoin infrastructure

The disclosure comes amid a wider period of security scrutiny around Bitcoin-related services. Another recent case involved Zeus Wallet, which temporarily took infrastructure offline after containing a cyberattack and began auditing its systems before bringing services back. Zeus said at the time that no customer funds were lost or put at risk and that its investigation had not found a flaw in Lightning node software.

Separately, crypto.news reported that the volunteer Bitcoin Red Team had identified thousands of potential issues while reviewing Bitcoin projects, with some findings labeled high or critical. Those incidents have added to concern around the security posture of wallet, payments, and node-related infrastructure across the ecosystem.

Next confirmed step for operators

BTCPay Server’s current instruction remains unchanged: update to version 2.4.2 immediately or keep the server offline until the patch can be installed. Until the project releases more technical detail, that is the only confirmed mitigation it has provided.

Administrators may also want to review server activity for signs of unauthorized access, but the project has not yet published specific evidence to look for. Any broader assessment of impact will likely depend on future disclosures once more systems have been patched and public technical details no longer increase the risk to unprotected servers.

Source: crypto.news