Theblock.Co Urgent Security Alert: BTCPay Server Vulnerability Actively Exploited
Article Content
- •BTCPay Server has a critical vulnerability being actively exploited, risking fund loss.
- •Users must update to version 2.4.2 immediately or shut down their servers.
- •No specific details on the attack vector or number of affected instances have been disclosed.
On August 7, 2026, BTCPay Server disclosed a critical vulnerability that is actively being exploited, potentially leading to the loss of funds. Users are urged to update to version 2.4.2 immediately or take their servers offline. The exact attack vector and the number of compromised instances remain undisclosed. The vulnerability affects all versions prior to 2.4.2, but specific details about how attackers gain access have not been shared. This incident follows other recent security alerts in the Bitcoin ecosystem, including issues with Coldcard wallets. Operators are advised to check their server activity for unauthorized access, although no formal indicators of compromise have been provided. The urgency of the situation is heightened due to the ongoing exploitation of the vulnerability.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (4)
Following this threat?
Track BTCPay Server in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical WSO2 API Manager Vulnerability Under Active Exploitation A critical vulnerability (CVE-2026-5430) in WSO2 API Manager is being actively exploited, allowing unauthenticated attackers to forge admin tokens via JWT authentication bypass. This flaw, which has a CVSS score of 10.0, affects multiple WSO2 products including API Manager, Universal Gateway, Traffic Manager, and API…
Critical Linux Kernel Vulnerability CVE-2025-39682 Under Active Exploitation A critical vulnerability (CVE-2025-39682) in the Linux kernel allows remote code execution through mishandling of zero-length TLS records. This flaw affects kTLS-enabled hosts running vulnerable kernel versions, exposing them to attackers without authentication. CISA added this vulnerability to its Known Exploited…