Update 6 of 8
BTCPay Server Flaw Under Active Attack
BTCPay Server Patches Critical Flaw Being Exploited Live as Lightning Nodes Are Drained
BTCPay Server, the self-hosted open-source Bitcoin payment processor, shipped an emergency patch (2.4.2) on August 7 for a critical vulnerability it said was being actively exploited to drain funds, urging operators to update immediately or take servers offline. Lightning nodes run by hardware-wallet maker Foundation and zine Citadel21 were drained, some before the public warning. Operators were told to refresh macaroon credentials, rotate backend auth strings and move hot-wallet funds.
6 sources
- BTCPay Server suffers critical vulnerability exploit; official team urgently requests users to upgrade and replace credentials. · lookonchain.com · T2
- Lightning Nodes Drained As BTCPay Server Users Race To Patch · thedefiant.io · T2
- BTCPay Server patches critical bug under active exploitation · bsc.news · T2
- Bitcoin Payment Service BTCPay Warns Critical Flaw Is Under Active Attack · decrypt.co · T2
- BTCPay Server urges urgent update after critical vulnerability exploited · en.coin-turk.com · T2
- BTCPay warns of actively exploited vulnerability that could drain funds · theblock.co · T1