security
BTCPay Server Issues Urgent Update Warning Over Exploited Vulnerability
BTCPay Server has issued an urgent alert for users to update their nodes following active exploitation of a security flaw. Several entities, including hardware wallet maker Foundation, reported their nodes were compromised before the public warning was issued.
AS1 NewsSource: thedefiant.io
On August 7, 2026, BTCPay Server, a popular self-hosted Bitcoin payment processor, warned its users about a critical security vulnerability that is currently being exploited by attackers. The vulnerability has led to the compromise of multiple Lightning nodes operated by BTCPay users, including one operated by hardware wallet manufacturer Foundation. Reports indicate that some nodes were targeted and emptied hours before the security alert was publicly issued.
The company clarified that the flaw under attack is not the same as the one disclosed in its recent changelog update, suggesting a different or previously unreported security issue is at play. The alert urges all operators to update their BTCPay Server instances to version 2.4.2 or later to mitigate the risk of further exploitation.
This incident highlights ongoing security challenges within the Bitcoin and Lightning network infrastructure, emphasizing the importance of timely updates and vigilant monitoring by node operators. The breach of Foundation's node underscores the potential impact on hardware wallet integrations and the broader ecosystem.
BTCPay Server has not disclosed specific technical details of the vulnerability to prevent further exploitation but continues to investigate the incident. Users are advised to follow official guidance and ensure their systems are up to date to protect their assets.
The active exploitation of the vulnerability has resulted in the compromise and theft from Lightning nodes, affecting the security and integrity of user-operated Bitcoin payment infrastructure.