**BTCPay Server Warns of Critical Vulnerability Being Actively Exploited**

**BTCPay Server Warns of Critical Vulnerability Being Actively Exploited**

BTCPay Server has disclosed a critical vulnerability in its platform, stating it is “being actively exploited” and urging users to upgrade to version 2.4.2 immediately. The open-source payment processor, which facilitates bitcoin and Lightning transactions, highlighted the risk of unauthorized access but provided no details on the scale of the breach or potential financial losses.

The advisory, posted on its official X account, marks the first public acknowledgment of the issue. Users are being directed to apply the update to mitigate risks, though the nature of the vulnerability—whether related to code execution, data exposure, or another vector—remains unspecified.

Separately, the Coldcard exploit, which targeted Bitcoin-only wallets and reportedly resulted in $116 million in confirmed losses, is noted as a distinct incident. However, BTCPay’s disclosure underscores ongoing security challenges in the cryptocurrency ecosystem, where vulnerabilities can be exploited with significant financial consequences.

The lack of clarity on affected users or losses has raised questions about the broader impact of the vulnerability. Industry observers stress the importance of timely updates, particularly for self-hosted platforms like BTCPay, which rely on user diligence to maintain security.


Written by Daniel Brooks
Security Desk

Share