Bitcoin Payment Service BTCPay Cautions Critical Flaw Is Under Active Attack
Compiled by KHAO Editorial — aggregated from 1 source + 2 references discovered via search. See llms.txt for citation guidance.
★ Tier-1 Source
BTCPay Server warned users Friday that attackers are exploiting a critical vulnerability that could lead to stolen funds.
Key facts
- In August, Coldcard maker Coinkite said it suspected attackers used AI to find a firmware flaw linked to more than $100 million in stolen Bitcoin
- In May, security researcher Taylor Hornby used Anthropic’s Claude Opus 4.8 to find a four-year-old Zcash vulnerability that could have allowed attackers to create unlimited counterfeit ZEC
- In a post on X on Friday, the Bitcoin payment processor urged administrators to install version 2.4.2 and confirm the update in the server footer
- While BTCPay Server did not disclose whether AI played a part, the news comes as AI is increasingly finding flaws in crypto projects
Summary
In a post on X on Friday, the Bitcoin payment processor urged administrators to install version 2.4.2 and confirm the update in the server footer. “If you are unable to update right away, turn off your BTCPay Server to prevent unauthorized access until you can update,” the company wrote. BTCPay Server also told users to replace credentials known as macaroons and recreate the macaroons.db file and refresh authentication strings for other Lightning Network backends. “If you generated a hot on-chain wallet in BTCPay, you want to move those funds and recreate the wallet,” they added.