Radio
Now Playing
Quickyla Radio โ€” Click to play
Open โ†’
3 min left

BTCPay warns users to patch critical flaw immediately

BTCPay Server users must upgrade to version 1.12.4 or later immediately to fix a critical flaw (CVE-2024-52099) allowing remote code injection and fund theft. Failing to patch risks stolen payment daโ€ฆ

Bitcoin Payment Service BTCPay Warns Critical Flaw Is Under Active Attack
Decrypt โ€” 7 August 2026
Text:
3 0 0

Bitcoin payment processor BTCPay Server warned users on Monday to immediately upgrade to the latest software version following the discovery of a critical security flaw that attackers are actively exploiting.

The vulnerability, tracked as CVE-2024-52099, allows unauthenticated remote attackers to inject malicious code into the serverโ€™s database, potentially stealing payment information or redirecting funds. The flaw affects all versions prior to 1.12.4, which was released Monday. BTCPay also advised users to rotate all API keys, passwords, and credentials that may have been exposed during the attack.

BTCPay Server is an open-source payment system used by thousands of merchants, including nonprofits, small businesses, and even some large companies, to accept Bitcoin without relying on third-party processors like BitPay or Coinbase Commerce. It gained popularity because it gives users full control over their funds and private keys. The flaw was first reported on Sunday by security researcher โ€œ0xfoobar,โ€ who observed active exploitation attempts targeting unpatched servers. The issue stems from improper input sanitization in the serverโ€™s webhook and payment processing modules, enabling attackers to execute arbitrary SQL commands. Within hours of the disclosure, exploit code was published on GitHub and hacking forums, accelerating the attacks.

If attackers gain access, they can steal payment data, alter withdrawal addresses, or even take over the server entirely. BTCPayโ€™s team has urged users to check logs for suspicious activity and reset all credentials. The incident highlights the risks of self-hosted financial software, where security depends entirely on the userโ€™s ability to patch quickly. While BTCPay is decentralized and community-driven, this attack shows how a single flaw can threaten many businesses at once. Users who fail to update risk financial loss and reputational damage. The company is expected to release additional fixes in the coming days and is likely to face questions about why the vulnerability wasnโ€™t caught earlier in its code review process.

Read Full Story at Decrypt โ†’
Advertisement
React:
Sources
Sponsored

More to Read

Alonso pleased with Aston Martin upgrade as Newey targets 'โ€ฆ
๐Ÿ’ป Technology
Alonso pleased with Aston Martin upgrade as Newey targets 'respectability'
Sky Sports ยท 14 days ago
Apple announces Siloโ€™s season 4 return date
๐Ÿ’ป Technology
Apple announces Siloโ€™s season 4 return date
9to5Mac ยท 11 days ago
Anthropic upgrades Claude with new Opus 5 model, details heโ€ฆ
๐Ÿ’ป Technology
Anthropic upgrades Claude with new Opus 5 model, details here
9to5Mac ยท 14 days ago
Why Tesla Stock Crashed Today
๐Ÿ“ˆ Markets & Finance
Why Tesla Stock Crashed Today
Nasdaq News ยท 14 days ago
Hereโ€™s the biggest news you missed this weekend
๐ŸŒ World News
Hereโ€™s the biggest news you missed this weekend
NBC News ยท 12 days ago
Singapore Stock Market Tipped To Open In The Red
โš”๏ธ War & Conflict
Singapore Stock Market Tipped To Open In The Red
Nasdaq News ยท 14 days ago
Full view