BTCPay Server patches critical bug under active exploitation
Active Exploitation Confirmed, Immediate Update Required @BtcpayServer has issued an emergency security advisory after confirming that attackers are actively exploiting a critical vulnerabili
A
AnonymousCryptoCompass newsroom
August 7, 2026
2 min read
NEWS
CryptoCompass editorial visual for bitcoin coverage.
Active Exploitation Confirmed, Immediate Update Required
@BtcpayServer has issued an emergency security advisory after confirming that attackers are actively exploiting a critical vulnerability in its software. In a notice published on August 7, the open-source Bitcoin payment processor urged administrators to immediately update their installations to version 2.4.2, warning that systems running older versions remain exposed and that the flaw can result in the loss of funds.
BTCPay Server is a free, open-source, self-hosted Bitcoin payment processor that lets individuals and businesses accept $BTC and Lightning payments directly, with no fees or intermediaries.That structure reduces reliance on a centralized payment provider but places the responsibility for software updates on individual merchants and server administrators.
Operators are instructed to install the latest release through the server maintenance panel and verify that the footer displays version 2.4.2 after the update.Those unable to update right away are told to turn off their BTCPay Server entirely to prevent unauthorized access until they can patch.
The Bitcoin Red Team, credited for the responsible security disclosure, provided details to help the project address the vulnerability. Integrators should also upgrade NBXplorer to version 2.6.10 alongside the main server update.
Post-Patch Steps and Remaining Uncertainty
Applying the update is only part of the remediation. The team says operators must also completely refresh macaroons and backend authentication credentials after patching. Any funds held in a hot wallet generated inside BTCPay should be moved out before that wallet is recreated.
The project's release notes state: "This release contains fix of a critical vulnerability that is being actively exploited. You need to update as fast as you can."
While the team confirmed funds may be at risk, it remains unclear how many users have been exploited or how much has been lost. Details surrounding the attack are currently limited.BTCPay Server has not disclosed the attack method or total financial losses.
Memecoin activity is drawing fresh liquidity into the broader altcoin market. SUI, ICP, RENDER, ONDO, and TAO continue attracting attention due to ecosystem growth. Market participants are mo
The US Treasury sanctioned two Iranian crypto exchanges, Shelbit and Aban Tether, on Friday for facilitating transactions for the Islamic Revolutionary Guard Corps. This move expands the Trum
Cryptocurrency exchange Bybit has taken North Korea to court over the record $1.5 billion hack it suffered in 2025 and won an early order freezing some of the stolen funds. According to a Coi