The confirmation centers on BTCPay Server, the self-hosted, open-source software many merchants use to accept Bitcoin directly. The project published a security advisory tied to BTCPay Server 2.
The confirmation centers on BTCPay Server, the self-hosted, open-source software many merchants use to accept Bitcoin directly. The project published a security advisory tied to BTCPay Server 2.
A Bitcoin payment processor has confirmed that funds were stolen following a security incident tied to its merchant infrastructure, placing the spotlight back on the software that businesses rely on to accept Bitcoin payments.
The confirmation centers on BTCPay Server, the self-hosted, open-source software many merchants use to accept Bitcoin directly. The project published a security advisory tied to BTCPay Server 2.4.2, the reference point for the disclosed issue. For related coverage, see U.S. Spot Bitcoin ETFs Add $98.85M, Extend Inflow Streak.
BTCPay Server is not a custodial exchange. It is payment-processing software that businesses run themselves, which means an exploit at this layer reaches merchant operations rather than a single central pool of customer deposits. For related coverage, see Bitcoin Miners Resume Selling as BTC Offloads Rise.
At this stage, the confirmed fact is narrow: a vulnerability was disclosed and a patched release was issued. Broader details, including a precise accounting of how the flaw was abused in every case, remain open questions rather than settled facts.
Reporting indicates the incident involved draining merchant-side infrastructure. CoinDesk described the event as another Bitcoin infrastructure exploit that drained merchant Lightning nodes, pointing to funds held on the payment rails merchants operate.
Because affected funds sit on merchant-operated nodes rather than in a central custodian, the practical impact falls on businesses running the software and, potentially, on the payment flows they manage. A specific dollar or BTC figure for total losses is not established in the available evidence.
The most direct step for operators is the one the project itself points to: moving to the patched release. This mirrors guidance covered when the BTCPay emergency patch first exposed merchant-side Bitcoin security risk, where the fix path ran through updating vulnerable installations.
The remediation already announced is the release of a patched version, which is the standard response for an open-source project responding to a disclosed flaw. What remains unconfirmed is the full scope of losses, the number of affected merchants, and any law enforcement or forensic involvement, none of which are established in the current evidence.
This case fits a wider pattern of pressure on the tools around Bitcoin rather than the protocol itself. Similar concerns surfaced with the Coldcard hack that hit Bitcoin hardware wallets, and again when a Bitcoin AI security sprint flagged thousands of potential issues across the ecosystem’s codebases.
For merchants and their customers, the verifiable next step is straightforward: confirm which software version is running and apply the fix referenced in the project’s advisory. Further detail on losses and any investigation will depend on additional disclosures the project has not yet made public.
Disclaimer: This article is for informational purposes only and does not constitute financial or investment advice. Cryptocurrency and digital asset markets carry significant risk. Always do your own research before making decisions.
Quick access to the site tools and map-driven utility pages.
Follow the core desks readers use most across Bitcoin, altcoins, mining, events, and sponsored coverage.
© 2026 BitcoinInfoNews.com. All rights reserved.
Independent Bitcoin and crypto coverage with public trust, policy, and newsroom pages available sitewide.