Loading prices…
🩸BEARISH

BTCPay Server Exploit Drains Lightning Nodes, Hits Foundation

Standard BTCPay on-chain wallets are safe, but LND operators on v2.4.1 or earlier face remote node takeover via unauthenticated .macaroon file access.

BTCPay Server Exploit Drains Lightning Nodes, Hits Foundation
BTCPay Server Exploit Drains Lightning Nodes, Hits Foundation
BTCPay Server Exploit Drains Lightning Nodes, Hits Foundation
BTCPay Server Exploit Drains Lightning Nodes, Hits Foundation

Attackers drained Lightning nodes running BTCPay Server late Friday after exploiting a critical vulnerability that exposed the LND credential files protecting them, the BTCPay team said in an X post. The flaw let unauthenticated remote attackers obtain ".macaroon" files, which grant software permission to interact with an LND Lightning node, and use them to seize control and move funds. Hardware-wallet maker Foundation and bitcoin publication Citadel21 were both confirmed as victims, with Foundation CEO Zach Herbert saying attackers swept the company's Lightning node overnight. BTCPay told anyone running LND to update immediately to version 2.4.2 or take the server offline, with a full postmortem due in the coming days.

Why it matters

The vulnerability sits at the intersection of merchant adoption and Bitcoin infrastructure, hitting small businesses that accept bitcoin through Lightning rather than retail holders. BTCPay is one of the most widely deployed self-custody payment stacks in the ecosystem, used by merchants to accept BTC and Lightning without intermediaries. The credential flaw specifically compromised Lightning wallets using LND, while BTCPay's standard on-chain wallets generated inside the platform remained unaffected, narrowing the blast radius but not eliminating it: funds held inside LND's own on-chain wallet sit under the same compromised node. The Bitcoin Red Team, a group of developers that began pointing AI models at bitcoin codebases earlier this week, had reported the flaw to BTCPay before live exploitation, and the project's rationale for rapid disclosure was that outside attackers would arrive at the same bug.

Market impact

The incident lands during what the same Red Team called an "extremely bad" week for bitcoin software, after flagging 85 critical bugs across hundreds of projects. For Lightning adoption specifically, the timing is awkward: merchants weighing whether to accept BTC through self-hosted infrastructure now have a live exploit to point at, even though no protocol-level weakness in Lightning itself was involved.

Related tokens
$BTC

Frequently asked questions

  1. What is the BTCPay vulnerability and how does it work?

    The flaw lets unauthenticated remote attackers obtain LND ".macaroon" credential files from BTCPay Server deployments, granting them permission to interact with and drain the underlying Lightning node.

  2. Which BTCPay wallets are affected?

    Only Lightning nodes running LND are exposed. BTCPay's standard on-chain wallets generated inside the platform remain safe, though funds held in LND's own on-chain wallet still sit under the compromised node.

  3. Who has been confirmed as a victim so far?

    Hardware-wallet maker Foundation and bitcoin publication Citadel21 both confirmed Lightning nodes were swept. BTCPay has not disclosed total victims or the amount of bitcoin stolen.

  4. What should BTCPay users running LND do?

    Update to BTCPay Server version 2.4.2 immediately or take the server offline until the patch is applied. A full postmortem from BTCPay is expected in the coming days.

  5. Did the Bitcoin Red Team warn BTCPay before the attack?

    Yes. Members Craig Raw, Rob Hamilton, Calle, and Evan Kaloudis disclosed the vulnerability to BTCPay, which credited them and the wider Red Team for responsible disclosure and analysis.

Source attribution
Aggregated from CoinDesk · Verified · Last refreshed 1h ago
Open original →