BTCPay Server disclosed Monday that a critical vulnerability in versions before 2.4.2 allowed attackers to obtain LND admin macaroon credentials. Those credentials enabled control of connected wallets and nodes, making the flaw a direct risk to Bitcoin payment infrastructure.
Why it matters
The exploit ties BTCPay software security directly to wallet and node control. Operators running a version in the affected range face a direct risk to connected wallets and nodes, and the 2.4.2 cutoff is the key boundary for assessing exposure.
BTCPay supporters committed to a recovery bounty worth 10% of recovered funds, capped at 3 BTC for full recovery. The payout depends on funds being recovered, giving the response a defined financial incentive.
Market impact
The immediate impact is operational for the Bitcoin ecosystem. The incident places connected wallets and nodes at risk through LND admin credentials, while the 3 BTC cap defines the maximum stated recovery incentive. Recovery of funds and the handling of installations before 2.4.2 are the main concrete watchpoints.
Frequently asked questions
-
Which BTCPay versions were affected by the critical vulnerability?
The affected range was BTCPay versions before 2.4.2.
-
What credentials did the BTCPay flaw expose to attackers?
The vulnerability allowed attackers to obtain LND admin macaroon credentials.
-
What could attackers control with the exposed LND credentials?
The credentials enabled control of connected wallets and nodes.
-
How is the BTCPay recovery bounty calculated?
Supporters committed to pay 10% of recovered funds, capped at 3 BTC for a full recovery.
-
What is the immediate risk to Bitcoin payment infrastructure?
The incident creates a direct security risk for connected wallets and nodes through exposed LND admin credentials.
TheBlock