If you were affected by the recent BTCPay vulnerability and can share further information, especially the on-chain addresses where stolen funds were sent, please email security@btcpayserver.org
Reported addresses linked to exploits of vulnerable BTCPay Server instances:
19jSfadPiKa4aCefj4F7uEYbhMEt2L8SCH
17C7EZC1VTrXzSQneiaJv2W6tQh1vCRSnF
If your incident involved another address, please share it.
Our analysis confirms that the attacker used exposed LND .macaroon credentials to access funds. Only LND users are affected, but we recommend everyone update to BTCPay Server 2.4.2.
We found no evidence that on-chain or hot wallets created in BTCPay Server were affected.
Thank you to everyone in the community who sounded the alarm, helped us spread this information quickly, and contacted merchants. Please continue reaching out to BTCPay Server operators you know and ask them to update.
I am deeply sorry to the users who suffered devastating losses. If you were affected or have more questions my DMs are open.
🚨 A vulnerability affecting all BTCPay Server instances is being actively exploited.
Update immediately to v2.4.2 to mitigate.
We’ll publish a full post-mortem in the coming days. Alert anyone you know who runs BTCPay.
Retweet to amplify please
much of the childish negativity in Bitcoin comes from too many projects/companies fighting over the same limited pool of users, capital, and attention. If more had real product-market fit, they’d be too busy for this shit