BTCPay Server, a leading open-source Bitcoin payment processor, has warned that attackers are actively exploiting a severe software vulnerability. The organization urged users on Friday to immediately update to version 2.4.2 or shut down their servers to avoid potential unauthorized access or loss of funds.
Immediate action recommended
In an advisory shared on X, BTCPay Server recommended that administrators confirm the update by checking the version displayed in the server footer. The project stressed that users who cannot update right away should turn off their BTCPay Server until the security patch is applied. Company representatives asserted, “If you are unable to update right away, turn off your BTCPay Server to prevent unauthorized access until you can update.”
For those using Lightning Network integrations, BTCPay Server instructed administrators to replace credential files known as macaroons, recreate the macaroons.db file, and refresh authentication strings in other Lightning Network backends. Users managing hot on-chain wallets through BTCPay Server were told to transfer their funds and set up new wallet addresses.
If you generated a hot on-chain wallet in BTCPay, you want to move those funds and recreate the wallet.
The organization credited the Bitcoin Red Team, a community of security researchers focused on Bitcoin ecosystem security, for identifying and reporting the vulnerability.
BTCPay Server did not release further details about the vulnerability itself, including how it operates, when the attacks began, the number of compromised systems, or whether any funds have been stolen so far.
Broader concerns over AI-assisted attacks
While BTCPay Server did not mention whether artificial intelligence contributed to detecting or exploiting the flaw, the incident comes amid a surge in AI-assisted security breaches across the cryptocurrency sector.
Earlier this year, security researcher Taylor Hornby used Anthropic’s Claude Opus 4.8, a generative AI platform, to uncover a longstanding Zcash vulnerability. That flaw, left undiscovered for four years, could have enabled attackers to mint unlimited counterfeit ZEC coins.
Mini dictionary: Claude Opus 4.8 — An advanced artificial intelligence model developed by Anthropic, designed to analyze code, detect vulnerabilities, and assist in cybersecurity research tasks.
In another incident last August, hardware wallet manufacturer Coinkite suggested that AI was used to spot a firmware vulnerability that subsequently led to more than $100 million in stolen Bitcoin.
Most recently, Bitcoin swap service provider Boltz paused operations after a series of exploits. Boltz reported that AI-driven attacks were discovering security flaws at a pace that outstripped the company’s ability to resolve them.
Ongoing developments
BTCPay Server has not made further public statements regarding whether any funds were taken or how many systems were affected in the current incident. The organization also has not responded to additional requests for comment.
| Project | Type of Vulnerability | AI Involvement | Impact |
|---|---|---|---|
| BTCPay Server | Critical software flaw | Not confirmed | Potential fund loss |
| Zcash | Protocol vulnerability | Detected using Claude Opus 4.8 | Risk of unlimited coin creation |
| Coinkite Coldcard | Firmware flaw | Suspected | Over $100 million stolen |
| Boltz | Multiple exploits | AI-assisted attacks | Service suspended |
Security experts continue to monitor the growing influence of AI in both discovering vulnerabilities and assisting with cyberattacks throughout the digital asset ecosystem. Organizations are being urged to respond rapidly to emerging risks and prioritize timely software updates.





USDT
AAPL
