Bitcoin (BTC) BTCPay Server Issues Emergency 2.4.2 Fix After Active Exploit
BTC/USDT
$13,392,455,202.61
$65,390.99 / $64,166.00
Change: $1,224.99 (1.91%)
+0.0003%
Longs pay
AI SummaryAI
- BTCPay Server warned that a critical vulnerability in its Bitcoin payment software is being actively exploited.
- The advisory instructs administrators to install version 2.4.2 or shut down servers until they can update.
- More than 1,700 BTC were stolen in the recent Coldcard attack referenced alongside the BTCPay warning.
- Foundation’s Zack Herbert said a company node was emptied overnight, while the Citadel 21 Lightning node was also drained.
Bitcoin News
Bitcoin (BTC) payment infrastructure came under fresh scrutiny on Friday after BTCPay Server disclosed that a severe software flaw is already being exploited by unidentified attackers. The project, an open-source and self-hosted processor used by merchants and node operators, said the vulnerability can lead to loss of funds and urged administrators to act immediately. The issue was disclosed by Bitcoin Red Team, a volunteer security group that has been reviewing open-source projects after the recent Coldcard attack tied to more than 1,700 BTC in stolen funds. In its public alert, BTCPay Server said the safest course is to move to version 2.4.2 through the admin dashboard and verify the version string in the server footer. Operators unable to patch right away were told to shut the service down until the update is complete. The advisory also recommended refreshing macaroons, recreating the macaroons.db file, rotating authentication strings, and transferring any coins held in wallets generated by the platform. Early field reports pointed to targeted draining rather than random scanning. Foundation co-founder and Chief Executive Zack Herbert said one of the company’s nodes was emptied overnight, while community member Hodlonaut flagged that the Citadel 21 Lightning node had also been drained, though it reportedly held limited balances because of precautions around a possible BIP-110 activation. The pattern suggests the attackers focused on tools used by highly motivated Bitcoin enthusiasts and infrastructure builders. That makes the episode more than a routine bug warning: it tests the resilience of the self-sovereign payments stack at a time when the broader Bitcoin ecosystem is already dealing with sophisticated attacks against hardware and software supply chains. At least two public cases of emptied nodes have surfaced, but the total impact remains unclear because the project has not published a formal incident tally. That gap leaves operators relying on fast patching and credential rotation rather than a centralized compensation process.
The second and more operational angle is the set of mitigation steps BTCPay Server has put in front of its user base. In a public notice posted Friday, the payment processor told administrators to install version 2.4.2 and confirm the build label in the server footer, rather than assume an automatic update succeeded. For teams that cannot patch immediately, the instruction is blunt: switch the server off to block unauthorized access. The notice also asks users to replace exposed credentials known as macaroons, rebuild the macaroons.db file, and refresh authentication strings used by Lightning Network backends. Anyone who generated a hot on-chain wallet inside BTCPay is advised to move those funds and create a fresh wallet. The project has not explained the mechanics of the flaw, the start date of the attacks, the number of affected servers, or any role played by AI. That absence of a public tally makes the incident harder to size, but it also underscores a broader shift in threat modeling. A May case showed the risk when Taylor Hornby, a security researcher, used Anthropic’s Claude Opus 4.8 model to uncover a four-year-old Zcash weakness that could have enabled unlimited counterfeit ZEC. In August, Coinkite, maker of Coldcard hardware, said it suspected AI-assisted discovery of a firmware flaw tied to stolen Bitcoin worth more than $100 million. On Tuesday, Bitcoin swap provider Boltz paused operations after several exploits, saying automated attacks were finding weaknesses faster than developers could patch. The same automation debate has surrounded AI Trading Bot software in markets, where speed advantages quickly become operational risk. For maintainers, patch cadence, credential hygiene, and rapid disclosure are becoming as important as feature development. This is not only a problem for an individual app; it is a stress test for the entire self-custody stack, from hobbyist nodes to merchant deployments.
COINOTAG’s analysis ties these developments to one theme: the Bitcoin (BTC) stack is entering a phase where security operations, not ideology, decide reliability. The primary record here is BTCPay Server’s own advisory, which explicitly directs users to install 2.4.2, shut down nodes if necessary, replace macaroons, rebuild macaroons.db, refresh Lightning authentication strings, and move hot-wallet funds. It does not provide a final loss figure or server count, so confirmed facts remain limited. That restraint matters. The lesson for operators is procedural: verify builds, rotate credentials, and isolate exposed wallets before assessing damage. In a market often distracted by an all-time high, this incident is a reminder that custody plumbing is still the system’s most fragile surface.
Add COINOTAG as a Preferred Source
Add COINOTAG to your preferred sources in Google News and Search to see our coverage first.
Add on GoogleRelated Tags
AI-generated, AI-reviewed, under COINOTAG editorial oversight.


