Particle.news

BTCPay Server Releases Emergency Patch as Critical Flaw Is Actively Exploited

Operators must install v2.4.2, refresh credentials, and move hot-wallet funds to prevent attackers from using stolen Lightning access to drain payments.

Overview

  • BTCPay Server published version 2.4.2 on Friday and warned that a critical vulnerability is being actively exploited and can lead to loss of funds.
  • The project told administrators to update through the admin dashboard and verify the footer shows 2.4.2 or immediately shut down exposed servers.
  • BTCPay gave specific remediation steps: replace macaroons, recreate the macaroons.db file, refresh Lightning authentication strings, upgrade NBXplorer if advised, and move any hot on-chain wallet funds to new wallets.
  • The team credited Bitcoin Red Team members for reporting the issue and said it will publish a full post-mortem, but it has not released technical details, indicators of compromise, the attack method, how many servers were hit, or confirmed losses.
  • The incident highlights a key self-hosting trade-off because macaroons are long-lived Lightning credentials that can survive some updates, meaning administrators must act fast or risk theft while balancing downtime and lost sales.