2.4.2:1
·
20 commits
to master
since this release
What's Changed
Prompts you to replace your Lightning node's credentials after the 2.4.2 security update.
The vulnerability patched in 2.4.2 was being actively exploited, so on any server that ran an earlier build, treat everything BTCPay Server could reach as exposed. Updating does not by itself undo access an attacker already took.
If BTCPay Server is wired to a Lightning node, updating raises a critical task and stops BTCPay Server until you clear it:
- LND — run LND's "Revoke Macaroons" action. BTCPay Server reads LND's admin macaroon, which grants full control of the node. This needs LND
0.21.1-beta:11or later, now required as a dependency: earlier releases called the action "Recreate Macaroons" and only deleted the macaroon files, leaving the root key that signs them in place, so nothing was actually revoked. - Core Lightning — run Core Lightning's "Revoke All Runes" action. BTCPay Server reaches CLN over its admin RPC socket, so a compromised server could have issued itself a rune that outlives the patch.
Two things this update cannot do for you:
- If you have ever connected BTCPay Server to a Lightning node — even if you have since switched away — rotate that node's credentials anyway. The task is only raised for the node BTCPay Server is wired to right now.
- If you generated a hot on-chain wallet inside BTCPay Server, move those funds to a wallet whose keys BTCPay Server has never held. A hot wallet's keys cannot be rotated.
Downloads
SHA256 Hashes
344ee9b2a1ec62e9c5f73a9b60486b82df5efef8f27b4a710b12f005c018d41a btcpayserver_aarch64.s9pk
3ca788801736972d336fa61f819f3221802146f3c15db57b83712346efb9b174 btcpayserver_x86_64.s9pk