BTCPay Docker Users Must Opt Into Tor to Retain Onion Access

iconCryptoSlate
Share
AI summary iconSummary
BTCPay Server users deploying via Docker must now manually enable Tor to retain onion access, per on-chain news updates. The change, effective with version 2.4.5 released October 6, 2026, removes Tor from default components. Admins must run 'sudo btcpay-fragments add opt-add-tor' during setup or updates. Existing Tor data remains intact, but onion access will stop without active inclusion. Inflation data and network metrics remain unaffected by the update.

Operators running the Bitcoin payment software BTCPay Server through its standard Docker deployment must explicitly select Tor at their next setup or update if they want to retain onion access. The change removes Tor from the automatically included components, making a previously bundled service an administrator’s configuration choice.

BTCPay detailed the deployment change in its Oct. 5 announcement accompanying version 2.4.5. The official GitHub release page records the software release on Oct. 6. For existing installations, the relevant trigger is their next Docker setup or update.

Related Reading

Malicious bots are actively probing exposed Bitcoin payment servers to steal master administrative keys

The change matters to Docker operators who rely on Tor, including access through their server’s onion address, but previously received it through the core BTCPay Server fragment. Fragments are the configuration components used to assemble the Docker stack.

BTCPay advises administrators to review the deployment changes before updating. After updating to 2.4.5, its instruction for enabling Tor is:

sudo btcpay-fragments add opt-add-tor

Tor remains supported, and BTCPay says existing data stays in the current Tor volumes. That preserves stored data; continued onion access still depends on including and running Tor in the deployment.

Related Reading

Bitcoin Core’s privacy fix reaches v32 code while the v31 patch remains open

BTCPay Server documentation describes the optional Tor fragmentopt-add-tor as adding hidden services and selected onion connectivity. Operators can inspect configuration using btcpay-fragments show, which does not change configuration and reports saved additional and excluded fragments alongside the effective fragments from the last generated manifest.

Fragment-changing commands require root and reapply setup immediately.

BTCPay Docker maintenance flow showing Tor configuration inspection, the post-update opt-add-tor command, preserved Tor volumes and the distinction between data retention and uninterrupted onion access.

Private services need separate exceptions

The 2.4.5 release notes also identify a breaking change for outbound HTTP requests: private-network destinations are blocked by default for Lightning connections, LNURL requests, invoice notification URLs and webhooks. The restriction is intended to prevent server-side request forgery, or SSRF.

With that protection enabled, operators intentionally using private services must allow the needed destinations through ssrfexceptions.

BTCPay’s operator guide says to restart the application and exercise the affected integration after changing the setting.

Related Reading

Lightning Labs discloses critical bug marking canceled invoices paid, risking free product delivery

The post BTCPay Docker users must opt into Tor at their next update to keep onion access appeared first on CryptoSlate.

Disclaimer: The information on this page may have been obtained from third parties and does not necessarily reflect the views or opinions of KuCoin. This content is provided for general informational purposes only, without any representation or warranty of any kind, nor shall it be construed as financial or investment advice. KuCoin shall not be liable for any errors or omissions, or for any outcomes resulting from the use of this information. Investments in digital assets can be risky. Please carefully evaluate the risks of a product and your risk tolerance based on your own financial circumstances. For more information, please refer to our Terms of Use and Risk Disclosure.