Overview
- BTCPay Server released version 2.4.2 Friday and told operators to install it immediately or take exposed servers offline because the project says attackers are actively exploiting a critical flaw.
- The team advised updating through the app’s Admin Dashboard and verifying the update by checking that the footer shows “2.4.2,” and it warned against using unofficial patches or downloads.
- BTCPay Server has not named which prior releases are vulnerable, explained the attack method, reported how many servers were hit, or confirmed any funds lost; the team promised a full post-mortem in the coming days.
- The emergency highlights a core tradeoff of self-hosting: merchants must choose between immediate downtime that stops exposure and staying online with a known exploit that could jeopardize payments and customer funds.
- The disclosure follows other recent Bitcoin infrastructure incidents and large volunteer security reviews, raising broader scrutiny of payment tooling and prompting operators to review and harden their setups.