BTCPay Server Removed Tor From Default Deployments
The software update separates Tor as an optional component and enforces new security restrictions.
Updated on Oct. 10, 2026 in Remote Work

Live Poll
Do you prefer more manual control over your server's security settings even if updates become complex?
BTCPay Server version 2.4.5 has officially removed Tor as an automatically included component within Docker deployments. Users who wish to maintain onion access must now manually select the Tor fragment during the installation or update process.
Why it matters
The change includes a default block on outbound HTTP requests to private-network destinations to prevent server-side request forgery. This update impacts how administrators handle Lightning connections, webhooks, and invoice notifications.
BTCPay Server version 2.4.5 introduces the separation of Tor as an optional configuration component. The update forces a default restriction on outbound HTTP requests to private networks.
The players
BTCPay Server
BTCPay Server is an open-source, self-hosted cryptocurrency payment processor that allows merchants to accept payments without third-party intermediaries.
GitHub
GitHub is the primary platform used by the development team for hosting and distributing the official software releases.
The details
Operators retain access to existing Tor data in current volumes, though they must configure specific exceptions to allow private service destinations. The security measure applies specifically to Lightning connections, LNURL requests, invoice notification URLs, and webhooks.
Timeline
October 5, 2026: BTCPay Server announced the deployment change.
October 6, 2026: Version 2.4.5 was officially released.
Market Landscape
This shift reflects a broader trend among self-hosted financial platforms to prioritize security hardening by default, moving away from legacy configurations that may expose servers to request forgery. It positions BTCPay Server to better mitigate risks in complex, multi-service environments while maintaining support for advanced users.
Administrators must manually adjust their Docker setup to restore Tor connectivity if they rely on onion services for daily operations. Failure to configure exceptions may cause disruptions to webhooks, Lightning network traffic, and invoice notifications.
The takeaway
Operators should review their current deployment configurations to ensure that critical services remain reachable under the new security protocols. Manually enabling required fragments ensures that privacy features remain active without sacrificing the protection against server-side request forgery.
Further reading
For more information on self-hosted infrastructure, visit the Remote Work section.
Source note: This article includes information reported by CryptoSlate.
Live Poll
Do you prefer more manual control over your server's security settings even if updates become complex?







