BTCPay Server is under active exploitation of a critical vulnerability, posing an immediate risk of fund loss for merchants using the payment processor. The project urged administrators Friday to install patched version 2.4.2 without delay.

The flaw affects how BTCPay Server validates and records incoming payments. Attackers can interfere with invoice processing and payment verification, triggering incorrect invoice status changes or marking invoices as paid without blockchain confirmation—a bypass that directly threatens the integrity of merchant transactions.

BTCPay Server outlined several mitigation steps alongside the mandatory update. Users must replace credentials known as macaroons and recreate the macaroons.db file, and must refresh authentication strings for any Lightning Network backends connected to their BTCPay instance.

Users who generated a hot on-chain wallet within BTCPay were advised to move all funds from that wallet immediately, then recreate the wallet. If an immediate software update is not possible, administrators were told to shut down their BTCPay Server and suspend automatic checkout processes until patches can be applied.

BTCPay Server has not disclosed how the flaw technically works, when the attacks began or how many servers have been compromised. The project also did not confirm whether any funds have been stolen. Developers said they discovered the issue after receiving reports of unusual transaction behavior, and credited Bitcoin Red Team members with reporting the vulnerability. The project said it is working with blockchain security researchers and independent auditors to analyze attack patterns, with further technical notes and refined detection rules expected after additional analysis.

This incident comes during a period of rising sophistication in crypto exploits, with several recent attacks suspected of using artificial intelligence to discover vulnerabilities. In August, Coinkite—maker of the Coldcard hardware wallet—said it suspected AI was used to find a firmware flaw linked to more than $100 million in stolen Bitcoin. Bitcoin swap provider Boltz suspended services earlier this week, citing AI-assisted attacks finding vulnerabilities faster than its team could patch them. In May, security researcher Taylor Hornby used Anthropic's Claude to identify a four-year-old Zcash vulnerability that could have allowed attackers to create unlimited counterfeit ZEC.

BTCPay Server is an open-source Bitcoin payment processor that enables merchants and services to accept on-chain and Lightning Network payments without relying on third-party intermediaries.

Merchants using BTCPay Server should verify transaction confirmations directly on the blockchain—particularly for large or time-sensitive payments—and review recent invoice and transaction logs for signs of manipulation.