BTCPay Server issues urgent v2.4.2 patch for critical vulnerability under active exploitation
BTCPay Server, the open-source, self-hosted Bitcoin and Lightning payment processor, has released version 2.4.2 with a fix for what it says is a critical vulnerability that is already being actively exploited, and it is urging operators to patch immediately.
In the official GitHub release notes for v2.4.2, published Aug. 7, BTCPay said: “This release contains fix of a critical vulnerability that is being actively exploited. You need to update as fast as you can.” The release page shows the patch was published at 15:31 and authored by Nicolas Dorier.
The warning matters because BTCPay Server is commonly run by merchants and service providers on their own infrastructure rather than through a third-party payment company. That self-hosted model gives operators more control, but it also means each deployment must be maintained individually. Systems that are not updated remain the responsibility of the operator and may stay exposed until a patch is applied.
Alongside the BTCPay update, the project said integrators should also update NBXplorer, a related blockchain indexing component used with many BTCPay deployments, to version 2.6.10. In the same release notes, BTCPay said: “We recommend integrators to also update NBXplorer to version 2.6.10. Those have been reported to us by @brunoerg and @benthecarman from the Bitcoin Red Team effort.”
Crypto.news reported Friday that BTCPay also advised operators to install version 2.4.2 immediately and, if they cannot update right away, to shut down their BTCPay Server until the patched version is installed. According to crypto.news, which said it was citing BTCPay’s official X account, operators should also verify after updating that their server footer shows v2.4.2.
Beyond that, BTCPay has disclosed little publicly about the issue. The advisory does not list a CVE number, describe the technical nature of the flaw, say which earlier versions are affected, or clarify whether the bug is in BTCPay Server itself or in a related component or plugin. BTCPay also has not publicly confirmed any number of compromised servers or any losses tied to the exploitation.
The limited disclosure is typical when a vulnerability is under active exploitation, as projects often prioritize getting users patched before releasing technical details that could help attackers. Still, for operators trying to assess exposure, key questions remain unanswered for now.
Whale Alert, a service that tracks blockchain activity and security notices, also amplified the warning on Telegram at 16:28 UTC on Friday. But the primary advisory came from BTCPay’s own GitHub release.
BTCPay Server is widely used by businesses that want to accept Bitcoin and Lightning payments without handing payment processing to a centralized intermediary. Because it is open-source and self-hosted, rapid patching is not automatic: each operator has to install updates and maintain related components such as NBXplorer on their own systems.