BTCPay Server has released version 2.4.5, focusing on security enhancements and performance improvements. The update, announced October 5, 2026, introduces protections against Server-Side Request Forgery attacks and tightens control over fund transfers.
Security and Privacy Changes
The release addresses Server-Side Request Forgery, or SSRF, a vulnerability that tricks servers into making unauthorized requests to internal systems. Version 2.4.5 adds protections across Lightning and LNURL outbound requests, plus invoice webhooks, restricting where the server will send traffic.
Refund authorization has been restricted to fewer team members, narrowing who can approve outbound fund transfers. Public invoice details will now be hidden one month after issuance, limiting how long payment pages broadcast transaction information.
Deployment and Performance
The Docker deployment received a significant update. Tor support is now optional rather than bundled by default, requiring existing users to manually re-enable it after updating. Invoice generation performance has been improved.
A new command, btcpay-routes, provides administrators greater control over Lightning API routes. Several older integrations—Bitcoin Plus, Trezarcoin, and JoinMarket—have been retired.
Developer Updates
Plugin Builder registration has reopened with improved sandboxing to isolate plugins and prevent faulty code from affecting other system components. New Greenfield APIs and database improvements accompany the release, alongside breaking changes that developers should review before upgrading production systems.
Recommendations for Operators
Administrators are advised to update through the server settings menu and immediately verify Tor configuration afterward. The stricter refund rules reduce both insider risk and exposure from compromised accounts. Developers with custom integrations or plugins should review GitHub release notes before upgrading production systems.


