BTCPay Server, the widely used open-source Bitcoin payment processor, has issued an urgent warning about a critical vulnerability that is being actively exploited. The team announced on their official X account on Friday that attackers are leveraging the flaw to potentially drain user funds, urging all node administrators to immediately update to version 2.4.2.
The exact attack vector remains undisclosed, and the total amount of losses is currently unknown. In their statement, BTCPay Server emphasized: "If you are unable to update right away, turn off your BTCPay Server to prevent unauthorized access until you can update." The advisory directs users to navigate to Admin Dashboard -> Server -> Maintenance -> Update to apply the patch and verify the version string in the footer.
This incident follows closely on the heels of another high-profile security breach—the Coldcard wallet exploit—which has already resulted in at least $116 million in confirmed losses. The coincidence amplifies concerns over Bitcoin custody and payment infrastructure, urging heightened vigilance across the ecosystem.