BTCPay Server Removed Tor From Default Deployments

The software update separates Tor as an optional component and enforces new security restrictions.

Updated on Oct. 10, 2026 in Remote Work

Isometric editorial illustration showing a modular server blade array with one disconnected fiber-optic cable segment, representing technical infrastructure configuration updates.
BTCPay Server version 2.4.5 has removed Tor as a default component, requiring administrators to manually configure onion-routing for specific network connections. AI Illustration. Upload story photo >

Live Poll

Do you prefer more manual control over your server's security settings even if updates become complex?

BTCPay Server version 2.4.5 has officially removed Tor as an automatically included component within Docker deployments. Users who wish to maintain onion access must now manually select the Tor fragment during the installation or update process.

Why it matters

The change includes a default block on outbound HTTP requests to private-network destinations to prevent server-side request forgery. This update impacts how administrators handle Lightning connections, webhooks, and invoice notifications.

BTCPay Server version 2.4.5 introduces the separation of Tor as an optional configuration component. The update forces a default restriction on outbound HTTP requests to private networks.

The players

BTCPay Server

BTCPay Server is an open-source, self-hosted cryptocurrency payment processor that allows merchants to accept payments without third-party intermediaries.

GitHub

GitHub is the primary platform used by the development team for hosting and distributing the official software releases.

The details

Operators retain access to existing Tor data in current volumes, though they must configure specific exceptions to allow private service destinations. The security measure applies specifically to Lightning connections, LNURL requests, invoice notification URLs, and webhooks.

Timeline

  1. October 5, 2026: BTCPay Server announced the deployment change.

  2. October 6, 2026: Version 2.4.5 was officially released.

Market Landscape

This shift reflects a broader trend among self-hosted financial platforms to prioritize security hardening by default, moving away from legacy configurations that may expose servers to request forgery. It positions BTCPay Server to better mitigate risks in complex, multi-service environments while maintaining support for advanced users.

Administrators must manually adjust their Docker setup to restore Tor connectivity if they rely on onion services for daily operations. Failure to configure exceptions may cause disruptions to webhooks, Lightning network traffic, and invoice notifications.

The takeaway

Operators should review their current deployment configurations to ensure that critical services remain reachable under the new security protocols. Manually enabling required fragments ensures that privacy features remain active without sacrificing the protection against server-side request forgery.

Further reading

For more information on self-hosted infrastructure, visit the Remote Work section.

Source note: This article includes information reported by CryptoSlate.

Live Poll

Do you prefer more manual control over your server's security settings even if updates become complex?