The self-hosted crypto payment processor alerted on a critical vulnerability that was being actively exploited by threat actors and recommended updating or turning off the service to avoid loss of funds. BTCPay Server reported that the Bitcoin Red Team found and disclosed the vulnerability.
Key Takeaways
BTCPay Server faced an active vulnerability exploit that allowed attackers to steal funds from users.Developers urged users to update to version 2.4.2 or shut down servers to prevent further losses.Following the Coldcard hack, multiple nodes were drained in what appears to be a targeted attack.BTCPay Server, an open-source, self-hosted cryptocurrency payment processor, has announced it is facing an ongoing attack by unknown threat actors affecting its codebase.
On social media, the BTCPay Server team stressed that there was a “critical vulnerability being actively exploited on BTCPay Server, which can result in the loss of funds.”
In addition, the project prompted users to refresh macaroons and macaroons.db, two core files of the server; refresh auth strings and move funds if they are stored on a hot wallet generated using BTCPay.
He stressed that this attack seemed targeted, aiming at “the very heart” of the bitcoin social layer. “Coldcard and BTCPayserver. These are enthusiast/hardcore tools, used by the people who live and bleed Bitcoin. This does not feel like chance,” he concluded.

















