Bitcoin Payment Service BTCPay Warns Critical Flaw Is Under Active Attack

CN
Decrypt
Follow
1 hour ago

BTCPay Server warned users Friday that attackers are exploiting a critical vulnerability that could lead to stolen funds.


In a post on X on Friday, the Bitcoin payment processor urged administrators to install version 2.4.2 and confirm the update in the server footer.





“If you are unable to update right away, turn off your BTCPay Server to prevent unauthorized access until you can update,” the company wrote.


BTCPay Server also told users to replace credentials known as macaroons and recreate the macaroons.db file and refresh authentication strings for other Lightning Network backends.


“If you generated a hot on-chain wallet in BTCPay, you want to move those funds and recreate the wallet,” they added.


The project credited Bitcoin Red Team members with reporting the vulnerability.


BTCPay Server has not disclosed how the flaw works, when the attacks began, how many servers were compromised, or whether any funds were actually stolen.


While BTCPay Server did not disclose whether AI played a part, the news comes as AI is increasingly finding flaws in crypto projects.


In May, security researcher Taylor Hornby used Anthropic’s Claude Opus 4.8 to find a four-year-old Zcash vulnerability that could have allowed attackers to create unlimited counterfeit ZEC.


In August, Coldcard maker Coinkite said it suspected attackers used AI to find a firmware flaw linked to more than $100 million in stolen Bitcoin.


More recently, on Tuesday, Bitcoin swap provider Boltz suspended its service after several exploits, saying AI-assisted attacks were finding vulnerabilities faster than its team could fix them.


BTCPay Server did not immediately respond to a request for comment by Decrypt.


免责声明:本文章仅代表作者个人观点,不代表本平台的立场和观点。本文章仅供信息分享,不构成对任何人的任何投资建议。用户与作者之间的任何争议,与本平台无关。如网页中刊载的文章或图片涉及侵权,请提供相关的权利证明和身份证明发送邮件到support@aicoin.com,本平台相关工作人员将会进行核查。

Share To
APP

X

Telegram

Facebook

Reddit

CopyLink