BTCPay Server patches critical bug under active exploitation
Active Exploitation Confirmed, Immediate Update Required @BtcpayServer has issued an emergency security advisory after confirming that attackers are actively exploiting a critical vulnerabili
A
AnonymousCryptoCompass newsroom
August 7, 2026
2 min read
NEWS
CryptoCompass editorial visual for bitcoin coverage.
Active Exploitation Confirmed, Immediate Update Required
@BtcpayServer has issued an emergency security advisory after confirming that attackers are actively exploiting a critical vulnerability in its software. In a notice published on August 7, the open-source Bitcoin payment processor urged administrators to immediately update their installations to version 2.4.2, warning that systems running older versions remain exposed and that the flaw can result in the loss of funds.
BTCPay Server is a free, open-source, self-hosted Bitcoin payment processor that lets individuals and businesses accept $BTC and Lightning payments directly, with no fees or intermediaries.That structure reduces reliance on a centralized payment provider but places the responsibility for software updates on individual merchants and server administrators.
Operators are instructed to install the latest release through the server maintenance panel and verify that the footer displays version 2.4.2 after the update.Those unable to update right away are told to turn off their BTCPay Server entirely to prevent unauthorized access until they can patch.
The Bitcoin Red Team, credited for the responsible security disclosure, provided details to help the project address the vulnerability. Integrators should also upgrade NBXplorer to version 2.6.10 alongside the main server update.
Post-Patch Steps and Remaining Uncertainty
Applying the update is only part of the remediation. The team says operators must also completely refresh macaroons and backend authentication credentials after patching. Any funds held in a hot wallet generated inside BTCPay should be moved out before that wallet is recreated.
The project's release notes state: "This release contains fix of a critical vulnerability that is being actively exploited. You need to update as fast as you can."
While the team confirmed funds may be at risk, it remains unclear how many users have been exploited or how much has been lost. Details surrounding the attack are currently limited.BTCPay Server has not disclosed the attack method or total financial losses.
Cryptocurrency exchange Bybit has taken North Korea to court over the record $1.5 billion hack it suffered in 2025 and won an early order freezing some of the stolen funds. According to a Coi
Researchers linked the CryptoJS vulnerability to coordinated cryptocurrency thefts exceeding $5.7 million across Bitcoin, Ethereum Tron Polygon Rootstock networks, affecting thousands. Faulty
XRP joins Crypto.com's Dual Invest lineup @cryptocom has added XRP to its Dual Invest product, expanding a roster that already includes Bitcoin, $ETH, $SOL, $USDC, and $PAXG. Dual Invest laun