BTCPay Server, an open-source Bitcoin payment processor, urgently released a patch after discovering a critical flaw that allows fund theft, with active exploitation already underway. Operators must immediately update to version 2.4.2 or shut down their servers while awaiting the fix. One user has already reported losing approximately 0.26 BTC. Additionally, a phishing campaign targeting Trezor users through fake Google ads allegedly stole approximately 24 BTC, worth nearly $1.6 million at current Bitcoin prices. These incidents follow a previous critical vulnerability in certain ColdCard seeds that led to the theft of approximately 600 BTC, worth nearly $38 million.
Source: Read the original article

