Twitter/X

Critical vulnerability in BTCPay Server is being actively exploited (reported…

Brief

BTCPay Server has a critical, actively exploited vulnerability reported 2026-08-08 that can let remote attackers drain LND (Lightning) node funds and may compromise hot-wallet Bitcoin and Monero. Administrators must upgrade to version 2.4.2 (Admin Dashboard -> Server -> Maintenance -> Update; verify '2.4.2' in the footer) or shut down the server until patched.

Why it matters

Critical vulnerability in BTCPay Server is being actively exploited (reported 2026-08-08); update to BTCPay Server 2.4.2 via Admin Dashboard -> Server -> Maintenance -> Update and confirm the '2.4.2' version string in the footer, or power off the server until patched.

Key details

  • The bug allows remote attackers to drain balances of LND (Lightning Network) nodes and may affect hot-wallet Bitcoin and Monero; addresses that use only public keys for Bitcoin and Monero are not affected (sources: @Zenul_Abidin, @BtcpayServer).
Source evidence

🚨PATCH YOUR BTCPAY NODES NOW!

A bug was discovered which allows remote attackers to drain the balance of LND Lightning Network nodes.

It may also affect hot wallet Bitcoin and Monero.

If you only use public keys for your Bitcoin and Monero addresses then you are not affected.

BTCPay Server (@BtcpayServer)

There is a critical vulnerability being actively exploited on BTCPay Server, which can result in the loss of funds.

Please update your BTCPayServer to 2.4.2 by going to Admin Dashboard -> Server -> Maintenance -> Update & verify the 2.4.2 version string in the footer.

If you are unable to update right away, turn off your BTCPay Server to prevent unauthorized access until you can update.

— https://nitter.net/BtcpayServer/status/2085755643659522240#m