BTCPay Urges Update After Attackers Steal Funds
BTCPay Server has urged operators to update immediately after attackers exploited a critical vulnerability in the self-hosted Bitcoin payment tool and stole funds from affected use...
BTCPay Server has urged operators to update immediately after attackers exploited a critical vulnerability in the self-hosted Bitcoin payment tool and stole funds from affected users. The BTCPay update after attackers steal funds arrived as version 2.4.2, shipped on August 7, 2026, with the project warning that the flaw was being actively exploited in the wild.
TLDR Keypoints
- BTCPay Server urged operators to update to v2.4.2 as fast as possible.
- Attackers actively exploited a critical flaw and stole funds from affected users.
- Applying the update is the immediate takeaway for anyone running the software.
What Happened in the BTCPay Attack
BTCPay Server, a widely used self-hosted Bitcoin payment processor, released version 2.4.2 on August 7, 2026 and labeled it a fix for a critical vulnerability that was being actively exploited, according to the official release. The notes urge operators to update as fast as possible. For related coverage, see Bitcoin and Ethereum ETFs Top $1B in Best Week Since April as BlackRock Takes 80%.
The v2.4.2 changelog lists a fix for a TOTP two-factor authentication bypass via Greenfield Basic authentication. The release also recommends integrators upgrade NBXplorer to version 2.6.10, a dependency step often overlooked when operators focus only on the main application. For related coverage, see Polymarket Faces $170K Lawsuit Over Trump Prediction Bet.
The exploit exposed LND macaroon credentials, and BTCPay confirmed that users were affected and that funds were stolen, BeInCrypto reported. The incident mirrors a wider pattern of Bitcoin infrastructure exploits draining merchant Lightning nodes.
Foundation and Citadel21 both said their Lightning nodes were swept, The Defiant reported, though no authoritative total for affected nodes or lost bitcoin has been published. According to unconfirmed reports based on developer Nicolas Dorier’s replies on X, the bug being actively exploited may differ from the Greenfield TOTP bypass disclosed in the public changelog; BTCPay had not yet released a promised technical postmortem.
Why the Update Matters for BTCPay Users
The people most exposed are merchants, wallet operators, and self-hosting Bitcoiners who route payments through BTCPay and its Lightning backend. Because stolen macaroon credentials can survive a software patch, updating alone may not fully close the door on attackers who already captured them.
BTCPay’s remediation guidance went beyond installing the patch, calling on operators to rotate macaroons, rebuild macaroons.db, refresh Lightning backend authentication strings, and move funds from hot on-chain wallets created inside BTCPay, Decrypt reported. That distinction between patching the software and fully remediating the incident is the practical heart of the story.
The event is an operational security failure in self-hosted infrastructure, not a weakness in the Bitcoin protocol itself, and spot markets reflected that. Bitcoin traded at $64,789 at research time, down just 0.2% over 24 hours, signaling limited broader market reaction.
Wider sentiment remained cautious rather than panicked, with the crypto Fear & Greed Index reading 31, in Fear territory. The subdued price action stands apart from the corporate-treasury momentum seen as Jack Dorsey’s Block boosted its Bitcoin holdings to 9,117 BTC and Strategy’s $15 billion financing push for Bitcoin, underscoring that the incident stayed contained to affected operators.
Disclaimer: This article is for informational purposes only and does not constitute financial or investment advice. Cryptocurrency and digital asset markets carry significant risk. Always do your own research before making decisions.
Author
Akita Inu
Akita Inu covers fast-moving crypto market updates, exchange news, and token ecosystem developments for CoinLive, with a focus on concise source-led reporting.