BTCPay Server patches critical bug under active exploitation
Active Exploitation Confirmed, Immediate Update Required @BtcpayServer has issued an emergency security advisory after confirming that attackers are actively exploiting a critical vulnerabili
A
AnonymousCryptoCompass newsroom
August 10, 2026
2 min read
NEWS
CryptoCompass editorial visual for bitcoin coverage.
Active Exploitation Confirmed, Immediate Update Required
@BtcpayServer has issued an emergency security advisory after confirming that attackers are actively exploiting a critical vulnerability in its software. In a notice published on August 7, the open-source Bitcoin payment processor urged administrators to immediately update their installations to version 2.4.2, warning that systems running older versions remain exposed and that the flaw can result in the loss of funds.
BTCPay Server is a free, open-source, self-hosted Bitcoin payment processor that lets individuals and businesses accept $BTC and Lightning payments directly, with no fees or intermediaries.That structure reduces reliance on a centralized payment provider but places the responsibility for software updates on individual merchants and server administrators.
Operators are instructed to install the latest release through the server maintenance panel and verify that the footer displays version 2.4.2 after the update.Those unable to update right away are told to turn off their BTCPay Server entirely to prevent unauthorized access until they can patch.
The Bitcoin Red Team, credited for the responsible security disclosure, provided details to help the project address the vulnerability. Integrators should also upgrade NBXplorer to version 2.6.10 alongside the main server update.
Post-Patch Steps and Remaining Uncertainty
Applying the update is only part of the remediation. The team says operators must also completely refresh macaroons and backend authentication credentials after patching. Any funds held in a hot wallet generated inside BTCPay should be moved out before that wallet is recreated.
The project's release notes state: "This release contains fix of a critical vulnerability that is being actively exploited. You need to update as fast as you can."
While the team confirmed funds may be at risk, it remains unclear how many users have been exploited or how much has been lost. Details surrounding the attack are currently limited.BTCPay Server has not disclosed the attack method or total financial losses.
Ripple plans to place XRP branding on the University of Louisville's basketball court, according to the reported headline. The move would put the XRP name in front of basketball fans, though
U.S. prosecutors are moving to seize roughly $61 million in cryptocurrency they say is tied to a black-market Iranian oil operation. The case is a civil forfeiture request, not a done deal, a
CoinShares estimates that AI compute generates about three times as much profit per megawatt (MW) as Bitcoin mining, a comparison that reframes how operators think about the electricity feedi