BTCPay Server 2.4.5: Enhanced Security, Faster Invoices
MissedBlock Desk · · 3 min read
Updated
BTCPay Server Releases Update With Enhanced Security and Faster Invoices
BTCPay Server has rolled out version 2.4.5, bringing significant improvements in security and invoice processing speed. However, a notable change requires attention from users operating their stores via the Tor network.
Tor Support Now Optional
A key adjustment in this release is that Tor support is no longer enabled by default. Users who rely on an onion address for their BTCPay Server instance will need to manually re-enable Tor after updating to ensure their service remains accessible. This change is particularly relevant for those using Docker deployments, which have undergone a substantial cleanup in this version.
Addressing Server-Side Request Forgery
The most significant security enhancement targets Server-Side Request Forgery (SSRF), a vulnerability where an attacker can trick a server into making requests on their behalf, potentially accessing sensitive internal systems. Version 2.4.5 introduces protections against SSRF across Lightning and LNURL outbound requests, as well as invoice webhooks, making the server more discerning about the traffic it forwards.
Stricter Refund and Privacy Measures
Refund processes have also been tightened, with the update requiring more stringent permissions for approval. This limits the number of individuals within a store’s team who can initiate outgoing payments, thereby reducing insider risks and the potential damage from a compromised account.
Privacy has also received a boost. Public invoice details will now be automatically hidden one month after an invoice is issued, preventing old payment pages from indefinitely broadcasting sensitive information.
Performance and Integration Updates
On the performance front, the development team has focused on accelerating invoice generation. The release also marks the retirement of several older, unmaintained integrations, including Bitcoin Plus, Trezarcoin, and JoinMarket.
A new command-line tool, btcpay-routes, has been introduced, granting administrators greater control over Lightning API routes. This offers operators more flexibility in managing and exposing their Lightning network configurations.
Developer-Focused Enhancements
Beyond these headline features, the GitHub release notes detail breaking changes, new Greenfield APIs, and improvements to plugins and database functionality. Greenfield serves as BTCPay Server’s API for building custom applications on the platform.
Furthermore, the Plugin Builder registration has reopened with enhanced sandboxing capabilities. Sandboxing isolates plugins, making it more difficult for faulty or malicious ones to affect the core system.
Previous Releases and Recommendations
Version 2.4.5 follows closely behind 2.4.4, released in September, and 2.4.2, released in August 2026, both of which also emphasized security enhancements.
For all BTCPay Server users, the primary recommendation is to update the software through the server’s settings menu. Immediately after updating, administrators are advised to verify their Tor configuration. Developers working with custom integrations, plugins, or scripts are urged to review the GitHub release notes for any breaking changes before upgrading production environments. The new one-month privacy default for public invoices is considered a sensible measure to limit the long-term exposure of payment details.
