Key Takeaways:
- BTCPay Server confirmed a critical vulnerability is being actively exploited
- Operators must update to version 2.4.2 or shut down servers immediately
- Post-patch steps include rotating credentials and moving hot-wallet funds
Key Takeaways:

BTCPay Server disclosed a critical vulnerability being actively exploited on its self-hosted Bitcoin payment software, urging operators to update to version 2.4.2 or shut down servers to prevent loss of funds.
"There is a critical vulnerability being actively exploited on BTCPay Server, which can result in the loss of funds," the project said on X on Aug. 7. "Please update your BTCPayServer to 2.4.2 by going to Admin Dashboard -> Server -> Maintenance -> Update & verify the 2.4.2 version string in the footer."
The open-source processor, built as an alternative to BitPay, told administrators unable to patch immediately to turn off their servers until the update is applied. After upgrading, operators should refresh all macaroon files and the macaroon.db database, rotate authentication strings used with Lightning Network backends, and move Bitcoin from any hot on-chain wallets created within BTCPay Server before generating new ones. The project credited members of the volunteer Bitcoin Red Team, including Rob Hamilton, Craig Raw, Calle, and Evan Kaloudis, for privately reporting the flaw through responsible disclosure. It has not disclosed which versions are affected, how many installations were compromised, or whether any thefts have been confirmed.
The warning lands during a broader security review of Bitcoin infrastructure. A separate exploit affecting Coldcard hardware wallets has led to at least $116 million in confirmed losses, according to The Block, while Zeus Wallet took its systems offline after an attack. The Bitcoin Red Team has flagged 4,962 potential issues across 390 Bitcoin-related projects, classifying 720 as high or critical severity.
For merchants running self-hosted payment infrastructure, the incident shows the trade-off of self-custody: no vendor can push a fix onto individual servers, leaving each operator responsible for applying patches promptly. The advisory also invites secondary phishing, as European watchdogs this week warned fraudsters were impersonating regulators and exchanges during the EU's MiCA transition to steer users toward fraudulent wallets. Operators should download updates only from official sources and verify all communications before acting.
This article is for informational purposes only and does not constitute investment advice.