BTCPay Server warned users Friday that attackers are exploiting a critical vulnerability that could lead to stolen funds.
The Bitcoin payment processor advised admins to install version 2.4.2 and verify the update in the server footer in a post on X on Friday.
The business stated, “If you are unable to update immediately, turn off your BTCPay Server to prevent unauthorized access until you can update.”
Additionally, BTCPay Server instructed customers to update authentication strings for additional Lightning Network backends, rewrite the macaroons.db file, and replace credentials known as macaroons.
“You want to move those funds and recreate the wallet if you generated a hot on-chain wallet in BTCPay,” they continued.
The Bitcoin Red Team members were acknowledged by the project for drawing attention to the issue.
How the vulnerability operates, when the assaults started, how many servers were affected, and if any money was truly taken have all being withheld by BTCPay Server.

https://x.com/BtcpayServer/status/2085755643659522240?s=20
The finding comes as AI is increasingly identifying vulnerabilities in cryptocurrency projects, albeit BTCPay Server did not reveal if AI was involved.
Using Anthropic’s Claude Opus 4.8, security researcher Taylor Hornby discovered a four-year-old Zcash vulnerability in May that would have let hackers to produce an infinite amount of fake ZEC.
Coldcard manufacturer Coinkite stated in August that it believed hackers had utilized AI to identify a firmware vulnerability connected to over $100 million in pilfered Bitcoin.
Boltz, a Bitcoin swap provider, halted its business on Tuesday following several exploits, claiming that AI-assisted assaults were identifying flaws more quickly than its staff could address them.
You need to login in order to Like









Leave a comment