BTCPay Server Exploit Drains Some Lightning Nodes

Attackers exploited a critical BTCPay Server flaw to access LND credential files and drain funds from some Lightning nodes. BTCPay urged affected operators to update to version 2.4.2 immediately or take servers offline while it prepares a full postmortem.

BTCPay Server Exploit Drains Some Lightning Nodes

What happened?

Attackers exploited a critical BTCPay Server flaw to access LND credential files and drain funds from some Lightning nodes. BTCPay urged affected operators to update to version 2.4.2 immediately or take servers offline while it prepares a full postmortem.

Why it matters

The incident matters because BTCPay is used by merchants and publishers that accept bitcoin payments, while Lightning is designed to make bitcoin transfers faster and cheaper. The exploit targeted infrastructure around payments rather than Bitcoin’s base chain, but it still created a direct operational risk for businesses holding funds in affected Lightning setups.

Attackers drained funds from some Lightning nodes connected to BTCPay Server after exploiting a critical vulnerability that exposed credentials used by LND, a widely used Lightning node implementation. BTCPay said users running LND should update immediately to version 2.4.2 or take their servers offline.

The incident matters because BTCPay is used by merchants and publishers that accept bitcoin payments, while Lightning is designed to make bitcoin transfers faster and cheaper. The exploit targeted infrastructure around payments rather than Bitcoin’s base chain, but it still created a direct operational risk for businesses holding funds in affected Lightning setups.

According to BTCPay, the flaw allowed an unauthenticated remote attacker to obtain “.macaroon” files, which can grant software permission to interact with an LND node. Attackers used those credentials to control affected nodes and move funds, including by draining Lightning channels.

BTCPay said its standard on-chain wallets, including hot wallets generated inside BTCPay, were not affected by this specific credential issue. However, funds in LND’s own on-chain wallet may still be at risk because they are controlled through the compromised Lightning node.

Reported victims included hardware-wallet maker Foundation and bitcoin publication Citadel21. BTCPay has not disclosed how many users were affected or how much bitcoin was stolen, and said it would release technical details after operators have had time to patch.

Source: CoinDesk

Keep exploring

Related stories

Trump Media Pulls Back From Crypto Treasury and Prediction Market Plans

Trump Media Pulls Back From Crypto Treasury and Prediction Market Plans

Trump Media is unwinding two Crypto.com ventures tied to a crypto treasury strategy and prediction markets. The move comes as new leadership redirects attention toward media, data licensing, and a planned merger with fusion energy company TAE.

Read
Trump Media Scraps Crypto.com CRO Treasury Deal

Trump Media Scraps Crypto.com CRO Treasury Deal

Trump Media, Crypto.com and Yorkville Acquisition have ended plans for a public company focused on accumulating and staking Crypto.com’s CRO token. The pullback also includes a separate ETF servicing arrangement, marking a shift away from parts of Trump Media’s earlier crypto expansion.

Read
Developer Warns Bitcoin Holders About Replay Risk From Possible BIP-110 Fork

Developer Warns Bitcoin Holders About Replay Risk From Possible BIP-110 Fork

Bitcoin developer Kevin Loaec warned that holders could lose real BTC if they try to sell coins created by a possible BIP-110 fork before the chains are safely separated. The risk centers on replay attacks, because both chains may initially accept the same signed transactions.

Read