BTCPay Server issued a critical security alert on August 7 regarding an actively exploited vulnerability directly threatening user funds. The project recommends an immediate update to version 2.4.2 or, failing that, a complete shutdown of the server to prevent unauthorized access. The team also advises regenerating macaroons, renewing Lightning Network credentials, and moving funds from hot wallets to a new wallet. The vulnerability was privately reported by researchers from the Bitcoin Red Team before public disclosure, following responsible disclosure practices. This incident follows a dark week for Bitcoin security, which has already seen over $116 million stolen through a seed generation flaw affecting Coldcard hardware wallets.
Source: Read the original article

