BTCPay Server says critical self-hosted payment software vulnerability is being actively exploited, urges immediate patching

BTCPay Server warned that a critical vulnerability in its self-hosted payment software is actively being exploited and could allow stolen funds. Operators were told to update immediately to version 2.4.2 through the admin maintenance interface or shut down servers until patched; no attack details or confirmed losses were provided.
AI Analysis
The summary reports an actively exploited critical vulnerability that could lead to stolen funds and instructs operators to patch immediately or shut down, indicating urgent security risk and potential direct market disruption.