btcpay and server issue an urgent security announcement: versions prior to 2.4.2 contain critical vulnerabilities
2026-08-09 14:53:32
According to CoinMeta, Wu said that btcpay and server issued an emergency security announcement stating that all versions prior to 2.4.2 (including the 2.4.2 candidate versions) contain a critical vulnerability. It has been confirmed that this vulnerability has been actually exploited by attackers, resulting in the theft of user funds. This vulnerability may allow unauthorized remote attackers to obtain the macaroon credential files of lnd (Lightning Network implementation), thereby controlling lnd nodes and transferring funds. The official team has confirmed that this vulnerability has been exploited and caused user funds to be stolen, and is urging users of lnd to immediately upgrade to btcpay 2.4.2 and lnd 0.21.1. btcpay server on-chain wallets are not affected, and the official team has not yet disclosed the specific amount of funds stolen.
Source:X
This content is for market information only and does not constitute investment advice.
Follow HKWDB official accounts to stay updated
Hot Articles
Refresh

Web3: Circle obtains New York trust license, expanding USDC custody business.
07-31 22:04

Tesla reportedly plans to divest its China business to pave the way for integration with SpaceX.
07-31 21:54

web3: Foreign media: RWA perpetual contracts may expand faster than tokenization
07-31 21:24

Web3: Foreign media: Analysts say the real catalyst for XRP is not the Clarity Act.
07-31 20:55

Foreign media: Trump's children's accounts are unlikely to replace comprehensive family financial planning
07-31 20:24

