BTCPay Server Changed Tor Default Deployment Rules

Merchants hosting their own payment nodes must manually re-enable Tor to maintain onion network routing.

Updated on Oct. 10, 2026 in Remote Work

Isometric editorial illustration showing a series of interconnected server blocks and conduits, representing a technical network infrastructure configuration.
BTCPay Server version 2.4.5 has shifted its default deployment, requiring administrators to manually re-enable Tor to maintain onion routing for payments. AI Illustration. Upload story photo >

Live Poll

Do you prefer more manual control over your server's security settings even if updates become complex?

BTCPay Server updated its software to version 2.4.5, removing Tor as an automatic component in Docker deployments. Operators using onion routing must now manually configure the fragment during setup to preserve existing network paths.

Why it matters

The change introduces a default block on outbound HTTP requests to private-network destinations to prevent server-side request forgery. This security hardening requires administrators to explicitly define exceptions for Lightning connections and webhooks.

The update to version 2.4.5 marks a shift from automatic inclusion to an optional configuration for Tor. While the update enforces a block on private-network requests for Lightning and webhooks, the full scope of existing nodes requiring manual re-configuration is not yet known.

The players

BTCPay Server

An open-source, self-hosted payment processing platform that enables merchants to accept cryptocurrency without intermediaries.

The details

Under version 2.4.5, the platform prevents outbound requests to private networks by default to mitigate request forgery risks. To restore access for Lightning connections, LNURL requests, or webhooks, operators must manually include the Tor fragment during their Docker setup. Existing Tor data remains on current volumes after the update, but connectivity remains inactive until the specific fragment is re-enabled.

Timeline

  1. October 5, 2026: BTCPay announced the shift in deployment architecture.

  2. October 6, 2026: Version 2.4.5 was officially released via GitHub.

Market Landscape

This adjustment follows the security patterns established by the OWASP Top 10 Server-Side Request Forgery vulnerabilities. It marks a clear shift toward 'secure by default' deployment architectures in self-hosted financial infrastructure.

Operators running BTCPay Server must review their Docker deployment scripts immediately to ensure necessary Tor fragments are included. Failure to update configurations will result in broken connectivity for existing Lightning channels and automated webhooks.

The takeaway

Self-hosted payment operators should prioritize auditing outbound network permissions whenever updating core node software. Check your current Docker configurations against the version 2.4.5 release notes to ensure all required service exceptions are explicitly defined.

Further reading

For more on managing distributed infrastructure, explore the Remote Work section.

Source note: This article includes information reported by CryptoSlate.

Live Poll

Do you prefer more manual control over your server's security settings even if updates become complex?