Live Prices
Bitcoin

BTCPay Server Version 2.4.5 Requires Manual Tor Opt-In for Docker Deployments

TheCryptoDesk Editorial · 2m read
BTCPay Server Version 2.4.5 Requires Manual Tor Opt-In for Docker Deployments

BTCPay Server operators running the open-source payment platform via standard Docker deployments must now manually opt into Tor during their next update to maintain onion network routing.

Following the release of version 2.4.5—announced on Oct. 5 and officially published to GitHub on Oct. 6—the software no longer automatically bundles Tor into core configuration fragments.

Tor Opt-In Command and Configuration Changes

Prior to version 2.4.5, Tor was included automatically in the standard Docker deployment stack. Under the new update, existing stored data remains saved in current Tor volumes, but active Tor connectivity and hidden service access require explicit administrator action. To enable the service after updating, system administrators must execute the command sudo btcpay-fragments add opt-add-tor with root privileges.

Operators can verify their server configuration by running btcpay-fragments show, which displays active, additional, and excluded fragments without altering settings. All fragment modification commands take effect immediately upon execution.

Private Network Destinations Blocked by Default

In addition to the Tor configuration change, BTCPay Server version 2.4.5 introduces a security restriction blocking private-network destinations by default for outbound HTTP requests. This change aims to prevent server-side request forgery (SSRF) vulnerabilities affecting:

  • Lightning connections
  • LNURL requests
  • Invoice notification URLs
  • Webhooks

Administrators relying on private network services must manually declare exceptions using ssrfexceptions and restart the application to maintain operational integrations. As node administrators manage infrastructure updates, maintaining system integrity remains vital alongside physical security considerations, such as recent security discoveries like Mark Karpelès finding a hidden spy chip in a sealed hardware wallet.

Key Takeaways

  • BTCPay Server v2.4.5 unbundles Tor from standard Docker setups, requiring manual opt-in.
  • Administrators must run sudo btcpay-fragments add opt-add-tor to retain onion access.
  • Outbound HTTP requests to private destinations are now blocked by default to prevent SSRF risks.
  • Operators using internal services or webhooks must configure exceptions via ssrfexceptions.

Why It Matters

This operational update shifts BTCPay Server toward a more modular deployment model while enforcing strict security defaults. By unbundling non-essential background services and blocking local network outbound traffic by default, the platform significantly shrinks the default attack surface for self-hosted merchant nodes.

Terms in this article

Read next