BTCPay Server Users Urged to Update After Critical Flaw Exploited to Steal Funds
BTCPay Server, a self-hosted Bitcoin payment processing tool used by merchants and small businesses to accept cryptocurrency, has confirmed that attackers actively exploited a critical security flaw to steal funds from users. The vulnerability affects any installation running a version earlier than 2.4.2.
The company has urged all operators to update their software immediately to close the security gap and prevent further losses. Details on how the attackers carried out the theft have not been fully disclosed, but the confirmation that funds were actually stolen underscores the seriousness of the flaw.
Businesses that accept cryptocurrency payments through self-hosted tools like BTCPay Server carry the responsibility of keeping that software patched, unlike centralised payment providers who manage updates on the merchant's behalf. Any business running an outdated version remains exposed to this attack until it upgrades.