BLOCKCHAIN
BTCPay Server Urges Immediate Update Following Exploit That Led to Stolen Funds
BLOCKCHAIN
BTCPay Server Urges Immediate Update Following Exploit That Led to Stolen Funds
BTCPay Server has confirmed that attackers exploited a vulnerability affecting versions prior to 2.4.2, resulting in stolen funds. The platform has released a security update and is urging users to update immediately.
Aug 10, 2026, 12:34 PM - Source: BeInCrypto
BTCPay Server, a widely used self-hosted Bitcoin payment processor, has disclosed that a critical security flaw was exploited by attackers, resulting in stolen funds for some of its users. The vulnerability impacted all BTCPay Server installations running versions earlier than 2.4.2.
According to the BTCPay development team, the flaw allowed unauthenticated remote actors to obtain .macaroon credential files used by LND, a popular Lightning Network implementation. Access to these credentials could potentially provide unauthorized control over user funds.
To address the vulnerability, BTCPay Server has released version 2.4.2, which contains a patch closing the exploit. All users operating prior versions are urged to update their systems immediately to reduce the risk of further attacks. The project has not disclosed the total amount of funds lost or the number of affected users at this stage.
As always, users are reminded to maintain up-to-date software and monitor official project channels for security advisories and updates.
Original source link: https://beincrypto.com/bitcoin-btcpay-server-exploit-funds-stolen/
Back to news