{"slug": "bitcoin-payment-service-btcpay-warns-critical-flaw-is-under-active-attack", "title": "Bitcoin Payment Service BTCPay Warns Critical Flaw Is Under Active Attack", "summary": "BTCPay Server warned users Friday that attackers are exploiting a critical vulnerability that could lead to stolen funds, urging administrators to install version 2.4.2 or shut down their servers. The Bitcoin payment processor advised replacing credentials known as macaroons and recreating the macaroons.db file, and moving funds from hot wallets. The project credited Bitcoin Red Team members with reporting the flaw but has not disclosed details or whether funds were stolen.", "body_md": "#### In brief\n\n- BTCPay Server said attackers are exploiting a critical vulnerability.\n- Users should update immediately or shut down their servers.\n- The project has not said whether AI was involved.\n\nBTCPay Server warned users Friday that attackers are exploiting a critical vulnerability that could lead to stolen funds.\n\nIn a [post](https://x.com/BtcpayServer/status/2085755643659522240?s=20) on X on Friday, the Bitcoin payment processor urged administrators to install version 2.4.2 and confirm the update in the server footer.\n\n“If you are unable to update right away, turn off your BTCPay Server to prevent unauthorized access until you can update,” the company wrote.\n\nBTCPay Server also told users to replace credentials known as macaroons and recreate the macaroons.db file and refresh authentication strings for other Lightning Network backends.\n\n“If you generated a hot on-chain wallet in BTCPay, you want to move those funds and recreate the wallet,” they added.\n\nThe project credited Bitcoin Red Team members with reporting the vulnerability.\n\nBTCPay Server has not disclosed how the flaw works, when the attacks began, how many servers were compromised, or whether any funds were actually stolen.\n\nWhile BTCPay Server did not disclose whether AI played a part, the news comes as AI is increasingly [finding flaws](https://decrypt.co/370232/frontier-ai-models-find-crypto-bugs-industry-isnt-ready) in crypto projects.\n\nIn May, security researcher Taylor Hornby used Anthropic’s [Claude Opus 4.8](https://decrypt.co/370128/claude-opus-4-8-review) to find a four-year-old Zcash [vulnerability](https://decrypt.co/370237/ai-discover-tech-vulnerabilities-zcash-latest-example) that could have allowed attackers to create unlimited counterfeit ZEC.\n\nIn August, Coldcard maker Coinkite said it suspected attackers used AI to find a firmware flaw linked to more than [$100 million](https://decrypt.co/374891/hardware-wallet-firms-warn-of-phishing-surge-as-coldcard-losses-near-130m) in stolen Bitcoin.\n\nMore recently, on Tuesday, Bitcoin swap provider Boltz [suspended](https://decrypt.co/374933/bitcoin-bridge-shuts-down-ai-finding-bugs-too-fast) its service after several exploits, saying AI-assisted attacks were finding vulnerabilities faster than its team could fix them.\n\nBTCPay Server did not immediately respond to a request for comment by *Decrypt.*", "url": "https://wpnews.pro/news/bitcoin-payment-service-btcpay-warns-critical-flaw-is-under-active-attack", "canonical_source": "https://decrypt.co/375159/bitcoin-payment-service-btcpay-critical-flaw-active-attack", "published_at": "2026-08-07 20:00:34+00:00", "updated_at": "2026-08-09 09:31:56.840146+00:00", "lang": "en", "topics": ["ai-safety"], "entities": ["BTCPay Server", "Bitcoin Red Team", "Taylor Hornby", "Anthropic", "Claude Opus 4.8", "Zcash", "Coinkite", "Boltz"], "alternates": {"html": "https://wpnews.pro/news/bitcoin-payment-service-btcpay-warns-critical-flaw-is-under-active-attack", "markdown": "https://wpnews.pro/news/bitcoin-payment-service-btcpay-warns-critical-flaw-is-under-active-attack.md", "text": "https://wpnews.pro/news/bitcoin-payment-service-btcpay-warns-critical-flaw-is-under-active-attack.txt", "jsonld": "https://wpnews.pro/news/bitcoin-payment-service-btcpay-warns-critical-flaw-is-under-active-attack.jsonld"}}