BTCPay Server warned users Friday that attackers are exploiting a critical vulnerability that could lead to stolen funds.
“If you are unable to update right away, turn off your BTCPay Server to prevent unauthorized access until you can update,” the company wrote.
BTCPay Server also told users to replace credentials known as macaroons and recreate the macaroons.db file and refresh authentication strings for other Lightning Network backends.
“If you generated a hot on-chain wallet in BTCPay, you want to move those funds and recreate the wallet,” they added.
The project credited Bitcoin Red Team members with reporting the vulnerability.
BTCPay Server has not disclosed how the flaw works, when the attacks began, how many servers were compromised, or whether any funds were actually stolen.
BTCPay Server did not immediately respond to a request for comment by Decrypt.

















