BTCPay Server warns of active exploit, urges immediate updates and wallet moves BTCPay Server on Friday warned operators that a critical vulnerability is currently being exploited in the wild and urged immediate action to avoid potential theft. In a post on X, the open‑source Bitcoin payment processor told administrators to upgrade to version 2.4.2 and verify the update by checking the version in the server footer. “If you are unable to update right away, turn off your BTCPay Server to prevent unauthorized access until you can update,” the project said, adding a series of follow‑up steps for Lightning and on‑chain wallet users. What BTCPay says admins should do now - Upgrade to BTCPay Server v2.4.2 and confirm the version in the server footer. - If you cannot update immediately, take the server offline to block further access. - Replace macaroons (the Lightning authentication credentials), recreate macaroons.db, and refresh authentication strings for any other Lightning Network backends. - If you generated a hot on‑chain wallet in BTCPay, move funds out and recreate the wallet. BTCPay credited members of the Bitcoin Red Team for reporting the vulnerability. The team did not disclose technical details, and BTCPay has not said how the flaw operates, when the attacks started, how many servers — if any — were compromised, or whether funds were actually stolen. AI and security: the broader context BTCPay did not indicate whether AI tools were involved in discovering this vulnerability. But the alert arrives amid growing concern that AI is accelerating the discovery of software and firmware flaws in crypto systems. In May, security researcher Taylor Hornby used Anthropic’s Claude Opus 4.8 to help find a four‑year‑old Zcash vulnerability that could have allowed creation of counterfeit ZEC. In August, hardware wallet maker Coinkite said it suspected attackers used AI to pinpoint a firmware flaw tied to more than $100 million in stolen Bitcoin. And this week, Bitcoin swap provider Boltz temporarily suspended services after multiple exploits, saying AI‑assisted attacks were finding vulnerabilities faster than its team could respond. BTCPay has not yet responded to a request for comment sent by Decrypt. Operators of BTCPay Server and other self‑hosted Bitcoin services should treat this alert as high priority: patch immediately or take affected servers offline and follow the credential and wallet‑migration guidance to protect funds.
BTCPay Server Warns of Active Exploit, Urges Immediate Update to v2.4.2
ChainGPTShare
BTCPay Server has issued a warning about an active DeFi exploit targeting its platform. The open-source Bitcoin payment processor urged users to apply the BTC update to version 2.4.2 immediately. Admins unable to update were told to take servers offline, replace Lightning credentials, and secure hot wallet funds. The flaw was reported by the Bitcoin Red Team, though no technical details have been released.
Source:Show original
Disclaimer: The information on this page may have been obtained from third parties and does not necessarily reflect the views or opinions of KuCoin. This content is provided for general informational purposes only, without any representation or warranty of any kind, nor shall it be construed as financial or investment advice. KuCoin shall not be liable for any errors or omissions, or for any outcomes resulting from the use of this information.
Investments in digital assets can be risky. Please carefully evaluate the risks of a product and your risk tolerance based on your own financial circumstances. For more information, please refer to our Terms of Use and Risk Disclosure.