BTCPay Server issued an urgent warning about a critical vulnerability under active exploitation that directly risks user Bitcoin funds, demanding immediate action from all operators.

The project instructs users to patch their systems to version 2.4.2 immediately. Operators who cannot update must take their servers offline entirely to prevent potential fund drainage.

BTCPay Server is a free, open-source Bitcoin payment processor that lets merchants and individuals accept Bitcoin directly, bypassing third-party intermediaries and keeping users in self-custody.

This vulnerability follows a separate major breach at a Bitcoin wallet maker where an estimated $130 million in user funds was stolen. In that incident, the affected company said artificial intelligence tools failed to detect the exploited software flaw—raising concerns about relying solely on automated security audits.

Bitcoin currently trades at $64,925, up 0.8 percent over the last 24 hours.

Users running BTCPay Server installations must act now: update to 2.4.2 or pull the server offline. An active exploit is in the wild, and sitting on an unpatched instance is how funds disappear.