BTCPay Server Hit by Critical Vulnerability Attack, Urges Immediate Upgrade and Credential Change

- BTCPay Server has warned users of a serious vulnerability that is currently under active attack.
- Attackers could exploit this vulnerability to gain unauthorized access and potentially cause fund losses.
- Users are required to upgrade to version 2.4.2 immediately and verify that the update is complete.
- If users cannot upgrade in time, they are advised to temporarily shut down BTCPay Server to prevent further attacks.
- Users should replace possibly exposed macaroons credentials and refresh authentication strings for other Lightning Network backends.
PANews reported that Bitcoin payment processing project BTCPay Server has issued a warning regarding a critical vulnerability that is currently being exploited by attackers.
The vulnerability allows unauthorized access, which could lead to potential fund losses for users. To mitigate the risk, BTCPay Server has instructed users to upgrade to version 2.4.2 immediately and to check that the server footer confirms the update.
In cases where users are unable to perform the upgrade promptly, the official recommendation is to temporarily shut down the BTCPay Server to prevent any further attacks. Additionally, users are advised to replace any possibly exposed macaroons credentials and to refresh authentication strings for other Lightning Network backends.
BTCPay Server遭遇严重漏洞攻击,呼吁立即升级和更改凭证
PANews报道,Bitcoin支付处理项目BTCPay Server就当前正在被攻击者利用的严重漏洞发出了警告。
该漏洞允许未授权访问,可能导致用户资金损失。为了降低风险,BTCPay Server指示用户立即升级至2.4.2版本,并检查服务器底部是否确认更新完成。
如果用户无法及时进行升级,官方建议暂时关闭BTCPay Server以防止进一步攻击。此外,用户还被建议更换任何可能泄露的macaroons凭证,并刷新其他Lightning Network后端的认证字符串。