BTCPay Server discloses 'critical' vulnerability which may result in loss of funds
BTCPay Server1 has just released a security advisory2 detailing a critical vulnerability that is being actively exploited which may result in the loss of funds, urging operators to update or turn off servers immediately:
Please update your BTCPayServer to 2.4.2 by going to Admin Dashboard -> Server -> Maintenance -> Update & verify the 2.4.2 version string in the footer. If you are unable to update right away, turn off your BTCPay Server to prevent unauthorized access until you can update.
Advisory
1. a) Update from 2.4.1 to 2.4.2 or b) turn off servers until update is possbile
2. (after update) Completely refresh macaroons and macaroons.db
3. (after update) Completely refresh auth strings for other LN backends
4. for hot on-chain BTCPay wallets: move funds and recreate the wallet
It is worth mentioning that Bitcoin Red Team3 reported and helped address the vulnerability.
More details about this incident can be found in PR #74984.
Note that patching does NOT undo earlier compromise: credentials for instances that were reachable while unpatched must be treated as exposed.
This is an ongoing story and the report will be updated when new information is available.
-
https://btcpayserver.org/ ↩
-
https://farside.link/nitter/BtcpayServer/status/2085755643659522240 ↩
-
https://farside.link/nitter/callebtc/status/2085755935352328470 ↩