BTCPay Server has disclosed a critical vulnerability that the project says is being actively exploited in the wild. Operators are told to update to version 2.4.2 immediately or take their server offline until they can.
BTCPay Server: What to do now
The disclosure arrived through official BTCPay Server channels on August 7, 2026. The project’s guidance is direct: open Admin Dashboard, then Server, then Maintenance, and apply the update to 2.4.2. After updating, verify that the footer of your instance shows the 2.4.2 version string.
If you cannot apply the patch right away, the project’s recommendation is unambiguous: shut down the BTCPay Server instance entirely. An offline server cannot be exploited; a running, unpatched one can. The update process is straightforward for standard Docker deployments. For custom deployments, operators may need to pull the new version manually or use btcpay-update.sh from the command line.
Users who rely on third-party hosted BTCPay instances should confirm with their provider that the patch has been applied. The project warns that there is no third option that leaves your funds protected.
What BTCPay Server does
BTCPay Server is an open-source, self-hosted, non-custodial Bitcoin payment processor. Funds go directly from the customer’s wallet to the merchant’s wallet while the software monitors the blockchain and confirms when payments settle. The architecture aims to provide privacy, censorship resistance, and lower cost: there are no transaction fees beyond Bitcoin network fees and no intermediary that can freeze or delay funds. Responsibility for security and operations rests with whoever runs the server.
The software supports both on-chain Bitcoin payments and Lightning Network transactions and integrates with e-commerce platforms such as WooCommerce and Shopify. Major companies have integrated BTCPay Server; Namecheap has reportedly processed over $73 million in Bitcoin revenue through the platform.
Security context and technical details
The project has not published detailed technical information about the flaw, a common practice that gives users time to patch before releasing exploit details. What is known is that the vulnerability can result in the direct loss of funds. This suggests the issue may involve authentication bypass, wallet access, or transaction manipulation, but the project and the report caution that further speculation would be irresponsible at this stage.
The alert arrives amid broader warnings in the Bitcoin infrastructure space, including a separate Coldcard hardware wallet exploit that has resulted in tens of millions of dollars in losses, as reported by third parties.
BTCPay Server has handled critical vulnerabilities previously. In 2021, Tesla’s security engineering team responsibly disclosed a vulnerability affecting versions 1.0.7.0 and earlier; the project patched that issue within days. In late 2023 a vulnerability in the LNbank plugin, a third-party add-on that allowed BTCPay Server administrators to act as Lightning custodians, led to actual fund losses; one user reportedly lost 4 BTC and the plugin’s developer subsequently discontinued development.
The BTCPay Server project maintains a security contact at security@btcpayserver.org and accepts vulnerability reports through huntr.dev. The project has historically been responsive to disclosures and has paid bounties for significant findings.
Operators should act now: update to 2.4.2 and confirm the footer, or shut down the instance until the patch can be applied.

