BTCPay Server Critical Flaw Exploited, Lightning Nodes Drained
BTCPay Server confirmed a critical vulnerability actively exploited, leading to funds being stolen from Lightning Network nodes. Users are urged to update immediately or shut down servers.

BTCPay Server, the cryptocurrency payment processor, announced that a critical vulnerability actively exploited to target Lightning Network nodes has resulted in stolen funds. The company urged its users to immediately update their software to version 2.4.2 or take their servers offline.
The vulnerability in BTCPay Server allowed unauthenticated remote attackers to obtain `.macaroon` credential files for LND (Lightning Network Daemon). These credentials provided attackers with full control over an LND node, enabling them to move funds. Confirmed victims included prominent organizations such as hardware wallet manufacturer Foundation and Bitcoin publication Citadel21, both reporting drained Lightning nodes. The volunteer organization Bitcoin Red Team reportedly disclosed this vulnerability to BTCPay Server in advance, following an AI-assisted audit. In response, BTCPay Server released version 2.4.2 to fix the flaw and temporarily restricted remote access to the LND API on Docker deployments.
This incident once again highlighted the security risks inherent in self-hosted Bitcoin payment infrastructures. While BTCPay Server's standard on-chain wallets (including hot wallets) were not affected by this vulnerability, the risk specifically applied to deployments using LND and funds held in LND's own on-chain wallet. The attacks reportedly began on Friday night, with some nodes being drained before the public announcement. The total amount stolen and the number of affected operators have not yet been disclosed.
In the cryptocurrency markets, there was no significant immediate reaction in the price of Bitcoin (BTC) directly attributable to the incident. Bitcoin was trading around $65,000 at the time of the announcement, showing a slight upward trend. However, such security breaches can negatively impact trust and adoption of Layer-2 solutions built on the Bitcoin ecosystem, such as the Lightning Network. This event follows other recent security exploits, including Coldcard and Boltz, raising general security concerns within the broader Bitcoin infrastructure.
Analysts and market experts emphasize the critical importance for BTCPay Server users to immediately update and refresh their `.macaroon` credential files to mitigate the vulnerability. Stolen credentials could otherwise continue to grant attackers access even after a software update. Due to the nature of self-hosted solutions, each user is responsible for managing their own update process. This situation might lead some smaller operators to perceive the operational risk of decentralized Lightning solutions as too high, potentially pushing them towards centralized or custodial Lightning services. A more detailed technical post-mortem of the incident is expected in the coming days.
Related Symbols
₿ Want to ride this crypto move?
Open an account in minutes. Compare brokers offering crypto and start investing today — zero commission options available.
Comments (0)
No comments yet. Be the first to comment!