BTC ETH SOL BNB XRP Fear & Greed
AltcoinGordon
News

BTCPay Server Flags Critical Security Flaw Being Exploited in the Wild

The open-source bitcoin payment platform urges operators to act after reports of active attacks

Original AltcoinGordon illustration for: BTCPay Server Flags Critical Security Flaw Being Exploited in the Wild
Original illustration, drawn for this story by AltcoinGordon.

BTCPay Server has issued a warning about a critical vulnerability that attackers are actively exploiting, according to a report from Decrypt. The platform is a self-hosted, open-source payment processor that lets merchants accept bitcoin without relying on a third-party custodian.

BTCPay Server has built a reputation over the years as a privacy-focused alternative to hosted payment gateways. Businesses and individuals run their own instances, often on personal servers or virtual machines, to keep control of funds and transaction data. That independence is part of its appeal, but it also means security upkeep falls on each operator rather than a centralized provider.

A critical flaw under active attack raises the stakes for anyone running an exposed or outdated instance. Because BTCPay Server often connects directly to a user’s bitcoin wallet infrastructure, a successful exploit could potentially expose sensitive payment data or affect fund security. The specifics of the vulnerability, including which versions are affected, were not detailed in available reporting.

Self-custodied and self-hosted tools have become more attractive to bitcoin users seeking to avoid custodial risk. That same design, however, places the burden of patching and monitoring squarely on the operator. Security researchers have long noted that open-source infrastructure projects, while transparent, can become targets once a flaw is publicly disclosed or discovered by attackers scanning for vulnerable deployments.

The warning arrives amid a broader pattern of scrutiny around bitcoin infrastructure security. Custody arrangements, wallet software, and payment tooling have all faced periodic attacks as the amount of value flowing through decentralized systems grows. Any disclosed exploit targeting widely deployed software tends to prompt swift attention from the broader development and security community.

BTCPay Server’s maintainers, like those of many open-source projects, typically respond to such warnings with patches and guidance for operators. Users are generally advised to update to the latest supported version promptly and to review server configurations for unnecessary exposure. As more detail becomes available, the scope of affected deployments and the nature of the exploit are expected to become clearer.

Sources disagree on this story

This article was published before the reports below were compared. The reporting above stands; what follows is where the published accounts do not agree.

Decrypt's initial report on the BTCPay Server exploit leaves theft and on-chain wallet risk unconfirmed, while CoinDesk's later report says funds were confirmed stolen from Lightning nodes and on-chain wallets were not affected.

What all sources agree on

  • BTCPay Server warned that attackers are exploiting a critical vulnerability.
  • Users were told to update immediately to version 2.4.2 or take their servers offline.
  • The vulnerability involves LND macaroon credential files.
  • Bitcoin Red Team members were credited with reporting/disclosing the vulnerability.

Where the reports disagree

1Whether funds were confirmed stolen

BTCPay Server has not disclosed how the flaw works, when the attacks began, how many servers were compromised, or whether any funds were actually stolen.

Decrypt

BTCPay confirmed funds were stolen and told anyone running LND, the most widely used software for operating a Lightning node, to update immediately to version 2.4.2 or take the server offline.

CoinDesk

What would settle it: BTCPay Server's official postmortem or on-chain transaction records showing the drained Lightning channels.

2Whether on-chain wallets (including hot wallets) were at risk

If you generated a hot on-chain wallet in BTCPay, you want to move those funds and recreate the wallet,

Decrypt

BTCPay's standard on-chain wallets, including hot wallets, were not impacted by the vulnerability.

CoinDesk

What would settle it: BTCPay Server's official statement clarifying the scope of the vulnerability, or its technical postmortem.

What to make of it

Treat the existence of the vulnerability and the update instructions as established; do not treat claims about whether funds were actually stolen, or whether on-chain/hot wallets were at risk, as settled until BTCPay Server publishes its promised postmortem.

Market Impact

A critical vulnerability in payment infrastructure software does not directly move bitcoin's price, but it can affect confidence in self-hosted merchant tools. Businesses relying on BTCPay Server for direct bitcoin acceptance may face operational risk until patches are applied and verified.

Broader market impact is likely to be limited unless the exploit results in confirmed losses of funds or data at scale. Even so, incidents like this tend to reinforce ongoing debate in the crypto industry over the tradeoffs between self-custody and reliance on third-party custodians for security maintenance.

BTCPay Server's warning underscores the recurring security challenges facing open-source bitcoin infrastructure. Operators are advised to monitor official channels for patches and updates as more information emerges.

Frequently Asked Questions

What is BTCPay Server?

BTCPay Server is an open-source, self-hosted payment processor that allows merchants to accept bitcoin directly without using a third-party custodial service.

What did BTCPay Server warn about?

According to a report from Decrypt, BTCPay Server warned that a critical security flaw in its software is being actively exploited by attackers.

Who is affected by this vulnerability?

Operators running self-hosted BTCPay Server instances, including merchants and individuals accepting bitcoin payments, could be affected if their deployments are unpatched or exposed.

What should BTCPay Server users do now?

Users are generally advised to update to the latest supported software version and review their server configurations, while watching for further guidance from BTCPay Server's maintainers.