S&P 5007,709.96▼0.2% Nasdaq26,348.35▼0.1% Dow53,885.10▼0.8% Russell 2K3,001.55▼0.6% 10-Yr4.67%+5bp VIX15.15−0.66 WTI$78.07▲3.8% Gold$4,292.00▲1.1% EUR/USD1.152▼0.3% BTC$64,907▲1.0% Nikkei65,101▼1.8%
At close · Fri, Aug 7, 2026
Daily Market Updates.

Crypto

HomeCryptoMarket StructureBTCPay Server warns of critical vulnerability under ac…

BTCPay Server warns of critical vulnerability under active attack

BTCPay Server urged operators to update to version 2.4.2, replace exposed macaroons credentials, and recreate the macaroons.db file to reduce the risk of stolen funds.

BTCPay Server, the Bitcoin payment processor, warned that attackers are actively exploiting a critical vulnerability that could lead to stolen funds. The company urged administrators to either update immediately or shut down their BTCPay Server instances until the fix is applied.

In a post shared on X, BTCPay Server said operators should install version 2.4.2 and confirm the update in the server footer. If admins cannot update right away, the company recommended turning off the servers to prevent unauthorized access.

BTCPay Server also told users to replace macaroons, the credentials it says may have been exposed, and to recreate the macaroons.db file. It further said administrators should refresh authentication strings for other Lightning Network backends and, if they generated a hot on-chain wallet in BTCPay, move those funds and recreate the wallet.

The company has not disclosed how the flaw works, when the attacks began, how many servers were compromised, or whether any funds were stolen. In its update, Decrypt noted that the alert comes as security reporting has increasingly pointed to faster vulnerability discovery driven by AI-assisted techniques across crypto projects.

Latest closeBitcoin $64,906.59 ▲1.0%

More like this

Sources

Get the close, explained.

One email every trading day: what moved, why it moved, and what's on deck tomorrow. Read in 3 minutes.

Free. Unsubscribe anytime.