BTCPay Server disclosed a critical vulnerability this week that attackers are already exploiting in the wild. The open-source bitcoin payment processor is telling users to update to version 2.4.2 or switch the service off entirely to avoid losing funds. The flaw was found and disclosed by the Bitcoin Red Team. For anyone running the software, the message is simple: don't run an unpatched version.
An exploit, not a warning
The advisory doesn't read like a routine patch notice. BTCPay Server said threat actors are actively exploiting the vulnerability, which puts every operator on the clock. This isn't a bug that might get abused someday. It's being used right now, and the people running it need to treat it that way.
The Bitcoin Red Team found the issue and reported it. The group's disclosure gave the project a window to respond, and the recommendation that followed was stark: update immediately, or take the service down. The fact that the exploit is live makes that choice urgent rather than precautionary.
Update to 2.4.2, or turn it off
BTCPay's guidance is blunt. Upgrade to version 2.4.2, or disable the service until you can. That second option matters. For a payment processor, going dark means no incoming payments. The project is recommending it anyway, which tells you how serious the exposure is.
Operators running older versions are the ones who need to move first. If you can't patch right away, the safer move is to go offline until you can. Losing a few hours of incoming payments beats losing funds, and that's the trade-off the project is drawing.
The self-hosted trade-off
BTCPay Server is built to run on your own hardware. That's the draw, no middleman holding your coins or your data. The flip side is that you own the patching. When a critical vulnerability lands with active exploitation, the gap between the fix being available and the fix being applied is where funds get lost.
Anyone running BTCPay should check their version now and update to 2.4.2, or take the service offline until they can. The exploit is already active, so the clock is running. The next move belongs to the operators.




