BTCPay Server has warned users that a critical flaw in its Bitcoin payment service is under active attack. The company told users to install the latest version of the server and replace credentials that may have been exposed.
The warning matters because BTCPay Server is used to process Bitcoin payments, making server security and credential protection central to its users’ operations. A vulnerability under active attack raises the urgency for operators to patch quickly and review access details.
BTCPay’s guidance centers on two immediate steps: update to the latest server release and rotate potentially exposed credentials. The company did not, in the supplied material, provide additional details about the scope of affected users or the nature of the attacks.
For crypto companies and merchants that rely on self-hosted payment infrastructure, the incident is a reminder that wallet-adjacent systems can carry operational risk even when funds are managed outside traditional payment rails. Keeping software current and replacing exposed access credentials are basic safeguards when a flaw is being exploited.
Users running BTCPay Server should follow the company’s update instructions and treat any potentially exposed credentials as compromised. The available source material does not state whether customer funds were affected.