BTCPay Server critical vulnerability under active exploitation

Modern server rack with blue lighting in a secure data center environment.

In brief

  • BTCPay Server critical vulnerability under active exploitation enables fund theft
  • Update to version 2.4.2 immediately via Admin Dashboard > Server > Maintenance > Update
  • Take servers offline immediately if unable to patch until update is installed
  • Verify latest version running after completing the update

Immediate action required

BTCPay instructed users to update to version 2.4.2 immediately via the Admin Dashboard. The update path is straightforward: navigate to Server > Maintenance > Update and verify the 2.4.2 version string in the footer.

For operators unable to apply the patch right away, BTCPay recommended taking servers offline until the update could be installed. This precaution prevents exploitation during the window before patching is complete.

Verification and next steps

Operators should verify they are running the latest version after updating. The team emphasized the importance of this step to ensure the vulnerability has been fully remediated.

The incident underscores the critical need for vigilant self-hosting security practices. Self-hosted payment processors like BTCPay give merchants sovereignty over their infrastructure, but that autonomy carries responsibility — operators must stay on top of security updates. Active exploitation means the vulnerability isn't theoretical; attackers are actively leveraging it in the wild. Immediate action isn't optional.