Attackers drained funds from some Lightning nodes connected to BTCPay Server after exploiting a critical vulnerability that exposed credentials used by LND, a widely used Lightning node implementation. BTCPay said users running LND should update immediately to version 2.4.2 or take their servers offline.
The incident matters because BTCPay is used by merchants and publishers that accept bitcoin payments, while Lightning is designed to make bitcoin transfers faster and cheaper. The exploit targeted infrastructure around payments rather than Bitcoin’s base chain, but it still created a direct operational risk for businesses holding funds in affected Lightning setups.
According to BTCPay, the flaw allowed an unauthenticated remote attacker to obtain “.macaroon” files, which can grant software permission to interact with an LND node. Attackers used those credentials to control affected nodes and move funds, including by draining Lightning channels.
BTCPay said its standard on-chain wallets, including hot wallets generated inside BTCPay, were not affected by this specific credential issue. However, funds in LND’s own on-chain wallet may still be at risk because they are controlled through the compromised Lightning node.
Reported victims included hardware-wallet maker Foundation and bitcoin publication Citadel21. BTCPay has not disclosed how many users were affected or how much bitcoin was stolen, and said it would release technical details after operators have had time to patch.