BTCPay Server, open-source software used by merchants to accept bitcoin payments directly without a third-party processor, issued an urgent warning on Friday, August 7, 2026, disclosing a critical vulnerability that attackers are actively exploiting. The project told administrators the flaw carries the potential for stolen funds and urged immediate action rather than a routine patch cycle.

Decrypt reported that BTCPay withheld several specifics of the disclosure — the exact vulnerability mechanism, when attacks began, how many servers have been compromised, and whether funds have actually been stolen — a common tradeoff in active-exploit disclosures meant to avoid handing a roadmap to attackers who haven't yet found the bug.

a pile of gold and silver coins sitting on top of each other
Photo by Traxer on Unsplash

What administrators are being told to do

BTCPay's guidance is unusually direct for a security advisory. Administrators are told to update to version 2.4.2 immediately and confirm the new version number appears in the server footer; if an immediate update isn't possible, the recommendation is to disable the server outright rather than leave it exposed. Beyond patching, BTCPay is telling operators to replace macaroon credentials and recreate the macaroons.db file, refresh authentication strings for Lightning Network backends, and move funds out of any hot on-chain wallets that were generated within BTCPay — then recreate those wallets from scratch.

Related: Coldcard Hack Losses Could Hit $130M, Galaxy Research Says

The latest in a rough month for bitcoin hardware and infrastructure

The flaw was originally surfaced by members of Bitcoin Red Team, and it lands amid a run of self-custody security failures. Just days earlier, a five-year-old firmware bug in Coinkite's Coldcard hardware wallets — present since March 2021 and traced to the device bypassing its dedicated hardware randomness chip in favor of a predictable software substitute — let an attacker drain 1,816 BTC from 5,200 addresses, with 1,082.65 BTC of that (about $70.2 million at the time) pulled from 1,196 addresses in a single 41-minute window on July 30. Boltz separately suspended service after what it described as AI-accelerated attacks.

A pattern worth taking seriously

Coinkite has said it is assisting Coldcard victims but has not offered compensation, and BTCPay's advisory gives no indication yet of whether affected merchants will be made whole either. For a payment stack that markets itself on removing custodial risk, an active exploit against the server software itself is the scenario the whole model is supposed to avoid — which is likely why BTCPay's response leans so heavily on telling operators to assume compromise and rotate everything, rather than wait for confirmation that they were hit.