BTCPay Server warns of actively exploited vulnerability affecting fund security; users urged to update to version 2.4.2 immediately.
Security & Exploits ·
BTCPay Server, an open source bitcoin payment processor, disclosed an actively exploited vulnerability and directed users to upgrade to version 2.4.2 immediately. The vulnerability poses a risk to fund security, according to the project's warning.
The disclosure came after the flaw began being leveraged in live attacks against deployed instances. The urgency of the update reflects the active exploitation happening in the wild rather than a theoretical threat window. BTCPay users running earlier versions remained exposed to potential fund drainage until patching.
Details on the technical nature of the vulnerability, the scope of affected instances, or whether any funds were already lost remain unclear from available disclosures. The timeline for when the flaw was first identified or reported to the project has not been specified.