BTCPay warns users to patch critical flaw immediately
BTCPay Server users must upgrade to version 1.12.4 or later immediately to fix a critical flaw (CVE-2024-52099) allowing remote code injection and fund theft. Failing to patch risks stolen payment daโฆ
Bitcoin payment processor BTCPay Server warned users on Monday to immediately upgrade to the latest software version following the discovery of a critical security flaw that attackers are actively exploiting.
The vulnerability, tracked as CVE-2024-52099, allows unauthenticated remote attackers to inject malicious code into the serverโs database, potentially stealing payment information or redirecting funds. The flaw affects all versions prior to 1.12.4, which was released Monday. BTCPay also advised users to rotate all API keys, passwords, and credentials that may have been exposed during the attack.
BTCPay Server is an open-source payment system used by thousands of merchants, including nonprofits, small businesses, and even some large companies, to accept Bitcoin without relying on third-party processors like BitPay or Coinbase Commerce. It gained popularity because it gives users full control over their funds and private keys. The flaw was first reported on Sunday by security researcher โ0xfoobar,โ who observed active exploitation attempts targeting unpatched servers. The issue stems from improper input sanitization in the serverโs webhook and payment processing modules, enabling attackers to execute arbitrary SQL commands. Within hours of the disclosure, exploit code was published on GitHub and hacking forums, accelerating the attacks.
If attackers gain access, they can steal payment data, alter withdrawal addresses, or even take over the server entirely. BTCPayโs team has urged users to check logs for suspicious activity and reset all credentials. The incident highlights the risks of self-hosted financial software, where security depends entirely on the userโs ability to patch quickly. While BTCPay is decentralized and community-driven, this attack shows how a single flaw can threaten many businesses at once. Users who fail to update risk financial loss and reputational damage. The company is expected to release additional fixes in the coming days and is likely to face questions about why the vulnerability wasnโt caught earlier in its code review process.
Read Full Story at Decrypt โ

