BTCPay Server Warns of Critical Vulnerability Under Active Attack
Security

BTCPay Server Warns of Critical Vulnerability Under Active Attack

August 8, 20263 min read

Developers of Bitcoin payment service BTCPay Server said attackers are actively exploiting a critical vulnerability that could lead to stolen funds. The team urged administrators to update their servers to version 2.4.2 immediately or shut them down in the meantime. The warning went out in a post on X on Friday. It's one of the best-known open-source tools for accepting Bitcoin payments, used by shops and independent sellers around the world.

What happened

In the X post, BTCPay Server said attackers are exploiting a critical vulnerability that could lead to stolen funds. The team hasn't disclosed how the flaw works, when the attacks began, how many servers were compromised, or whether any funds have actually been stolen.

The developers confirmed only that active exploitation is underway and urged administrators to install version 2.4.2, then confirm the update in the server's dashboard footer. For anyone unable to update right away, the company recommended turning off the server to prevent unauthorized access.

BTCPay Server is an open-source tool for accepting Bitcoin payments that merchants run on their own infrastructure to avoid intermediaries like traditional payment processors. That self-hosted model puts the responsibility for updates and security directly on server owners rather than a central company. Every hour of delay on the update raises the risk for real payments still flowing through an unpatched server.

According to the team, the attack targets the server software itself rather than any single wallet or exchange. That means the operators running their own BTCPay instance to accept customer payments are most exposed, not everyday Bitcoin holders using mobile apps.

What BTCPay Server is telling users to do

Beyond the update itself, the team published a list of extra steps for server owners. The recommendations cover more than the software update alone, extending to a full swap of key credentials.

  • Replace credentials known as macaroons, access tokens some Lightning Network implementations use in place of regular passwords, and recreate the macaroons.db file.
  • Refresh authentication strings for other Lightning Network backends.
  • Move funds out of any hot software wallet generated inside BTCPay and create a new one.

These steps mainly apply to operators who accept payments directly through their own server rather than through a third-party host.

BTCPay Server hasn't said how many servers were affected or whether attackers have already moved user funds.

Who found the vulnerability

The project credited members of Bitcoin Red Team for finding and reporting the flaw. That research group previously reported nearly 5,000 potential vulnerabilities across various Bitcoin projects, found during 30 hours of automated, AI-driven code review. Teams like this typically run source code through models trained to spot common bug patterns, then manually verify the candidates before disclosure.

BTCPay Server hasn't officially confirmed whether AI helped attackers find the hole in its defenses, but the incident fits a broader pattern. The company has not yet responded to Decrypt's request for further comment. For the open-source community, it's another sign that researchers and attackers are now reaching for similar tools to hunt for flaws.

The wider pattern of AI-assisted attacks on crypto projects

The BTCPay Server case isn't the first example of AI speeding up the hunt for vulnerabilities in crypto infrastructure. In May, security researcher Taylor Hornby used Anthropic's Claude Opus 4.8 to find a four-year-old Zcash vulnerability that could have allowed attackers to mint unlimited counterfeit ZEC.

In August, Coldcard maker Coinkite said it suspected attackers used AI to find a firmware flaw linked to more than $100 million in stolen Bitcoin. On Tuesday, swap provider Boltz suspended its service after a string of exploits, saying AI-assisted attacks were finding vulnerabilities faster than its team could patch them.

What links these cases is that the attacks zeroed in on infrastructure users run themselves: hardware wallets, peer-to-peer swap services, and self-hosted payment servers. Centralized exchanges with large security teams have so far shown up less often in these reports.

For everyday BTCPay Server users, the takeaway is practical. Servers that accept payments directly stay exposed until administrators install version 2.4.2 and replace their credentials, and every day of delay adds risk. For the rest of the market, the case is more of a reminder that AI-based tools are just as available to defenders as they are to attackers.

Comments

Your email address will not be published. Required fields are marked *

or verify by email