BTCPay Server warned users about a critical vulnerability that, according to Decrypt’s report, is already being exploited in an active attack. The company urged users to install the latest version of the server.

Users were also advised to replace credentials that may have been exposed. This means that applying an update alone may be insufficient if the previous access credentials have already been compromised.

The source is presented as a brief synopsis rather than the full text of the primary statement. Therefore, it is not yet clear which versions are affected, when the attack began, or how many deployments may have been impacted.