BTCPay Server, the open-source platform that lets merchants accept Bitcoin without relying on third-party payment processors, issued an emergency advisory on August 7 warning users of a critical security vulnerability that is already being exploited in the wild.
The instructions were blunt: update to version 2.4.2 right now, or shut your server down entirely.
What happened and what users need to do
The BTCPay Server team disclosed the vulnerability just minutes before the warning spread across social media, a timeline that suggests the team prioritized getting the fix out over crafting a polished announcement.
Users running any version prior to 2.4.2 are potentially exposed. The upgrade can be performed through the admin dashboard, and the team advised verifying the update by checking that “2.4.2” appears in the footer of the application after installation.
For anyone who can’t update immediately, the guidance is stark: turn off the server.
The BTCPay Server team said a full post-mortem will be published in the coming days, which should shed light on the nature of the exploit, how it was discovered, and the scope of any financial damage.
Why BTCPay Server matters
BTCPay Server has been operating since its first release in 2017, with major version 2.0 arriving in late 2024 and continuous incremental updates through 2026. It is used by individual merchants, nonprofit organizations, and businesses that want to accept Bitcoin without paying fees to intermediaries.
But self-hosting comes with a tradeoff that this incident illustrates with uncomfortable clarity. When you run your own infrastructure, you are also your own security team. If you miss an advisory like this one, nobody is going to update your server for you.
Prior to this incident, BTCPay Server’s most notable public vulnerability was CVE-2022-32984, a responsible disclosure affecting older POS components. The August 7 advisory marks the first emergency of comparable severity the project has publicly disclosed.
The broader security implications
The fact that the exploit was already being used before the public disclosure raises important questions. How long were attackers aware of the flaw before the BTCPay Server team caught it? Were any funds actually stolen, and if so, how much? The post-mortem should address these questions.
Merchants who rely on BTCPay Server for daily transactions face an immediate choice between downtime and exposure. An e-commerce store that turns off its payment processor during peak hours loses sales. One that stays online with a known vulnerability risks something far worse.
Disclosure: This article was edited by Editorial Team. For more information on how we create and review content, see our Editorial Policy.

2 hours ago
14









English (US) ·