Critical Vulnerability in BTCPay Server Requires Immediate Update to Prevent Fund Loss

Critical Vulnerability in BTCPay Server Requires Immediate Update to Prevent Fund Loss

First seen 8 Aug 2026, 01:37 UTC GlitchwireTheblock.Co 80% similarity 72.8

Article Content

Browse articles
ThreatCluster

BTCPay Server has issued a critical security alert regarding a vulnerability that is actively being exploited, potentially leading to the loss of funds. Users are urged to update to version 2.4.2 immediately or take their servers offline. The vulnerability was disclosed on August 7, 2026, and affects all instances of BTCPay Server that have not been updated. While the exact number of affected users and the extent of losses are currently unknown, the urgency of the situation is emphasized by the project's warning. BTCPay Server is a self-hosted Bitcoin payment processor that allows users to accept payments without intermediaries. This incident follows other recent security alerts in the Bitcoin infrastructure space, including a significant exploit affecting Coldcard hardware wallets. The project has a history of vulnerabilities, but this is notable for being actively exploited at the time of disclosure.

Key Points: • BTCPay Server vulnerability is actively exploited, risking user funds. • Users must update to version 2.4.2 or take servers offline immediately. • The vulnerability follows other recent security issues in Bitcoin infrastructure.

ThreatCluster AI How this analysis works

Timeline

2026-08-07
BTCPay Server vulnerability disclosed
BTCPay Server announced a critical vulnerability that is being actively exploited, urging users to update to version 2.4.2 or shut down their servers.
Glitchwire
2026-08-07
Coldcard wallet exploit reported
A separate security alert was issued regarding the Coldcard hardware wallet exploit, leading to confirmed losses of at least $116 million.
Theblock.Co

Community

Browse all →