BTCPay Server 2.4.5 tightens security and speeds up invoices
The latest release hardens Lightning requests, trims old Docker integrations, and makes Tor a manual opt-in after updating
BTCPay Server has shipped version 2.4.5, and the headline features are tighter security and faster invoices.
There is one catch worth reading twice. If your store runs over Tor, that support switches off after the update, and you will need to turn it back on yourself.
What changed in 2.4.5
The release was announced on October 5, 2026, with the GitHub tag landing around October 6, 2026. Lead developers Nicolas Dorier and Pavlenex are credited with the work.
The biggest security change targets something called Server-Side Request Forgery, or SSRF. Picture a receptionist who will phone any number a stranger hands them, including internal lines that should never be called from outside.
SSRF works the same way. An attacker tricks a server into making requests on their behalf, sometimes reaching systems that are supposed to stay private.
Version 2.4.5 adds protections against that risk across Lightning and LNURL outbound requests, plus invoice webhooks. Put simply, the server is now pickier about where it agrees to send traffic.
Refunds also got stricter. The update tightens the permissions required to approve them, which narrows who on a store’s team can send money back out the door.
Privacy got a tweak too. Public invoice details will now be hidden one month after an invoice is issued, so old payment pages stop broadcasting information indefinitely.
On the performance side, the team focused on making invoice generation faster.
The news moving money, markets, and the world—before your day starts.
Daily. Free. Join 34,000+ readers across crypto, finance, and policy.
Docker cleanup and the Tor caveat
The Docker deployment, which is how many operators install and run BTCPay Server, received a meaningful cleanup in this release.
Tor support is now optional rather than baked in. Existing users who rely on an onion address need to manually re-enable Tor after updating to keep that service reachable.
The release also retires several older integrations that were no longer being actively maintained, including Bitcoin Plus, Trezarcoin, and JoinMarket.
A new command, btcpay-routes, gives administrators more control over Lightning API routes, offering operators more flexibility in how their Lightning setup is exposed and managed.
Beyond the headline items, the GitHub release notes list breaking changes, new Greenfield APIs, and improvements aimed at plugins and database functionality. Greenfield is BTCPay Server’s API for building on top of the platform.
Plugin Builder registration has also reopened, now with improved sandboxing. Sandboxing keeps a plugin boxed into its own space so a bad or buggy one has a harder time touching the rest of the system.
A steady drumbeat of security releases
Version 2.4.5 follows 2.4.4, released in September, and 2.4.2, released in August 2026, both of which also leaned toward security work.
What this means for merchants and operators
For anyone running BTCPay Server, the practical advice is simple: update through the server settings menu, then check your Tor configuration immediately afterward. The project encourages administrators to update through the appropriate settings menus to pick up the changes.
The stricter refund rules matter for stores with multiple staff accounts. Refunds are one of the few flows that move funds outward, and tightening who can approve them reduces both insider risk and the damage from a compromised account.
The breaking changes deserve attention from developers. Anyone with custom integrations, plugins, or scripts built against older behavior should read the GitHub release notes before upgrading production systems.
The hidden-after-a-month rule for public invoices is a modest but sensible privacy default. Payment pages that linger forever can leak details about who paid what and when, and capping that exposure costs legitimate users very little.