Attackers emptied Lightning nodes belonging to BTCPay Server users on Friday, including one run by hardware wallet maker Foundation, after the self-hosted bitcoin payment processor warned that a critical vulnerability was being actively exploited and told merchants to update to version 2.4.2 or shut their servers down.
Because BTCPay is self-hosted, there is no operator who can patch on behalf of its users. Every merchant, exchange and wallet running the software has to apply the fix on its own machine, and the thefts were already underway before the warning went out. The software sits behind bitcoin checkout for Namecheap, which ran $73 million in BTC revenue across 1.1 million transactions through BTCPay between May 2020 and October 2024, along with hundreds of smaller merchants and several wallet backends.
"There is a critical vulnerability being actively exploited on BTCPay Server, which can result in the loss of funds," the project wrote at 11:51 a.m. ET. "If you are unable to update right away, turn off your BTCPay Server to prevent unauthorized access until you can update." The post passed 550,000 views within five hours.
Founder Nicolas Dorier published release 2.4.2 the same morning with a one-line warning at the top: "This release contains fix of a critical vulnerability that is being actively exploited. You need to update as fast as you can." The notes also tell integrators to upgrade NBXplorer, BTCPay's wallet-tracking backend, to version 2.6.10.










