Particle.news

BTCPay Server Issues Emergency Patch After Active Exploit

The project ordered operators to update or shut servers to stop an exploit and said a technical post-mortem will follow.

Overview

  • BTCPay Server released version 2.4.2 Friday and told operators to install it immediately or take exposed servers offline because the project says attackers are actively exploiting a critical flaw.
  • The team advised updating through the app’s Admin Dashboard and verifying the update by checking that the footer shows “2.4.2,” and it warned against using unofficial patches or downloads.
  • BTCPay Server has not named which prior releases are vulnerable, explained the attack method, reported how many servers were hit, or confirmed any funds lost; the team promised a full post-mortem in the coming days.
  • The emergency highlights a core tradeoff of self-hosting: merchants must choose between immediate downtime that stops exposure and staying online with a known exploit that could jeopardize payments and customer funds.
  • The disclosure follows other recent Bitcoin infrastructure incidents and large volunteer security reviews, raising broader scrutiny of payment tooling and prompting operators to review and harden their setups.