The confirmation centers on BTCPay Server, the self-hosted, open-source software many merchants use to accept Bitcoin directly. The project published a security advisory tied to BTCPay Server 2.
A Bitcoin payment processor has confirmed that funds were stolen following a security incident tied to its merchant infrastructure, placing the spotlight back on the software that businesses rely on to accept Bitcoin payments.
What the Bitcoin Payment Processor Confirmed
The confirmation centers on BTCPay Server, the self-hosted, open-source software many merchants use to accept Bitcoin directly. The project published a security advisory tied to BTCPay Server 2.4.2, the reference point for the disclosed issue. For related coverage, see U.S. Spot Bitcoin ETFs Add $98.85M, Extend Inflow Streak.
BTCPay Server is not a custodial exchange. It is payment-processing software that businesses run themselves, which means an exploit at this layer reaches merchant operations rather than a single central pool of customer deposits. For related coverage, see Bitcoin Miners Resume Selling as BTC Offloads Rise.
At this stage, the confirmed fact is narrow: a vulnerability was disclosed and a patched release was issued. Broader details, including a precise accounting of how the flaw was abused in every case, remain open questions rather than settled facts.
What Is Known About the Loss and User Impact
Reporting indicates the incident involved draining merchant-side infrastructure. CoinDesk described the event as another Bitcoin infrastructure exploit that drained merchant Lightning nodes, pointing to funds held on the payment rails merchants operate.
Because affected funds sit on merchant-operated nodes rather than in a central custodian, the practical impact falls on businesses running the software and, potentially, on the payment flows they manage. A specific dollar or BTC figure for total losses is not established in the available evidence.
The most direct step for operators is the one the project itself points to: moving to the patched release. This mirrors guidance covered when the BTCPay emergency patch first exposed merchant-side Bitcoin security risk, where the fix path ran through updating vulnerable installations.
What Happens Next for the Company and the Investigation
The remediation already announced is the release of a patched version, which is the standard response for an open-source project responding to a disclosed flaw. What remains unconfirmed is the full scope of losses, the number of affected merchants, and any law enforcement or forensic involvement, none of which are established in the current evidence.
This case fits a wider pattern of pressure on the tools around Bitcoin rather than the protocol itself. Similar concerns surfaced with the Coldcard hack that hit Bitcoin hardware wallets, and again when a Bitcoin AI security sprint flagged thousands of potential issues across the ecosystem’s codebases.
For merchants and their customers, the verifiable next step is straightforward: confirm which software version is running and apply the fix referenced in the project’s advisory. Further detail on losses and any investigation will depend on additional disclosures the project has not yet made public.
Disclaimer: This article is for informational purposes only and does not constitute financial or investment advice. Cryptocurrency and digital asset markets carry significant risk. Always do your own research before making decisions.