Overview
- BTCPay Server published version 2.4.2 on Friday and warned that a critical vulnerability is being actively exploited and can lead to loss of funds.
- The project told administrators to update through the admin dashboard and verify the footer shows 2.4.2 or immediately shut down exposed servers.
- BTCPay gave specific remediation steps: replace macaroons, recreate the macaroons.db file, refresh Lightning authentication strings, upgrade NBXplorer if advised, and move any hot on-chain wallet funds to new wallets.
- The team credited Bitcoin Red Team members for reporting the issue and said it will publish a full post-mortem, but it has not released technical details, indicators of compromise, the attack method, how many servers were hit, or confirmed losses.
- The incident highlights a key self-hosting trade-off because macaroons are long-lived Lightning credentials that can survive some updates, meaning administrators must act fast or risk theft while balancing downtime and lost sales.