Crypto

BTCPay Server critical vulnerability prompts urgent update warning

BTCPay Server said an exploited critical flaw could lead to lost funds, telling self-hosted operators to update to version 2.4.2 or shut down.

Theo Nakamura

By Theo Nakamura · Staff Writer

· 3 min read

BTCPay Server critical vulnerability prompts urgent update warning
Photo: Decrypt

BTCPay Server warned on August 7 that a BTCPay Server critical vulnerability was being actively exploited and could lead to lost funds. For merchants and other operators who run the self-hosted Bitcoin payments software, the immediate instruction was to install version 2.4.2 or take the server offline until they can, according to BTCPay Server's public warning reported by BeInCrypto and The Defiant.

The incident concerns BTCPay Server deployments, not the Bitcoin protocol. BTCPay Server is open-source software that allows businesses to accept bitcoin payments directly, and because it is self-hosted, each operator must apply the security update on their own system.

What should BTCPay Server operators do?

BTCPay Server directed operators to update through the administrative dashboard and confirm that version 2.4.2 is installed. Those unable to update right away were told to turn off their servers to prevent unauthorized access, according to BeInCrypto.

The reported cleanup steps extend beyond installing the patch. Operators should refresh Lightning macaroons, which are access credentials used by Lightning nodes, and change authentication strings used by other connected backends. Users who created a hot wallet, meaning a wallet connected to the internet, inside BTCPay Server were also told to move its funds and create a replacement wallet. Integrators should update the companion transaction-indexing tool NBXplorer to version 2.6.10, BeInCrypto reported.

  • Update BTCPay Server to version 2.4.2.
  • Shut down the server if an immediate update is not possible.
  • Replace Lightning macaroons and other backend credentials.
  • Move funds from, then recreate, BTCPay-generated hot wallets.
  • Update NBXplorer to version 2.6.10 where applicable.

What impact has been reported so far?

Public reports indicate that some Lightning-node funds were swept. The Defiant reported that Foundation chief executive Zach Herbert said the company's BTCPay payment-processing Lightning node was drained, while its hot wallet was unaffected. Herbert said the node's channels were closed and the funds removed.

Citadel21's operator also said its Lightning node had been swept, according to The Defiant. The report cited at least one additional operator describing drained funds, but no public total of affected nodes or bitcoin losses had been released.

The technical cause, affected version range and attacker identity were not established in the available reporting. Accounts of how the issue came to light also differ: BeInCrypto reported that the Bitcoin Red Team, a volunteer security group, disclosed the flaw, while The Defiant reported that BTCPay founder Nicolas Dorier credited Sparrow Wallet developer Craig Raw with analyzing the incident after an affected developer lost money and said the Red Team's scans had missed it.

For investors and Bitcoin users who do not operate a BTCPay Server, the warning does not describe a compromise of Bitcoin itself. The practical takeaway is narrower: businesses and services using their own BTCPay installation need to confirm their software and connected credentials have been addressed.

This story draws on original reporting from Decrypt.

More from Crypto

All Crypto