A critical vulnerability within the BTCPay Server platform is being actively exploited, prompting a call for immediate action from the developers. Users are advised to update their servers to version 2.4.2 without delay. The team recommends disabling servers if an update cannot be implemented swiftly in order to mitigate potential unauthorized access.
BTCPay Server, a free and open-source payment processor, facilitates direct bitcoin and Lightning payments for individuals and businesses. This vulnerability is reportedly being exploited currently. The Block has contacted BTCPay Server for further information regarding the developing situation.
Following an alleged exploit impacting Coldcard wallets resulting in approximately $116 million in confirmed losses, the urgency of patching BTCPay Server is heightened. Funds could be at risk if users do not take swift preventative measures. Security experts advise a precautionary shutdown if immediate updates are impossible.
The number of individuals and businesses affected by this ongoing exploitation remains currently unclear. The extent of funds potentially compromised also remains undefined as detailed information is scarce. This developing situation requires constant monitoring, with further updates expected as reporting from The Block progresses.
Written by Daniel Brooks
Security Desk