GoCheckMyCrypto.com
Crypto Cronkite And that's the way it is.
VerifiedDeveloping, single sourcenewssecuritybitcoin

Active exploit drains Lightning nodes running BTCPay; immediate patching required

Attackers exploited a critical vulnerability in BTCPay Server to steal credentials and drain Lightning nodes running LND software. BTCPay ordered immediate updates to version 2.4.2 or server shutdown. Hardware-wallet maker Foundation and the Citadel21 publication reported their Lightning nodes were swept. The Bitcoin Red Team disclosed the flaw rapidly, and attackers were already exploiting it against live servers.

Who this affects

Quoted from the advisory linked below. The desk does not restate it.

Affected
deployments using LND
Fixed in
version 2.4.2
What to do
update immediately to version 2.4.2 or take the server offline

Attackers exploited a critical vulnerability in BTCPay Server to steal credentials and drain Lightning nodes running LND, the most widely used software for operating a Lightning node, according to CoinDesk's reporting. BTCPay told anyone running LND to update immediately to version 2.4.2 or take the server offline.

The flaw allowed an unauthenticated remote attacker to obtain `.macaroon` files, or credentials that give software permission to interact with an LND Lightning node, per CoinDesk. BTCPay said the attacks it reviewed targeted those files, which could then be used to take control of the node and move funds. Attacks occurred late Friday after the vulnerability was exploited against live servers, according to CoinDesk's reporting.

Hardware-wallet maker Foundation was among the victims. Chief Executive Zach Herbert told CoinDesk attackers drained the company's BTCPay Lightning node overnight, closing its channels and sweeping the funds. Its BTCPay on-chain hot wallet was untouched. Citadel21, the bitcoin publication run by pseudonymous commentator hodlonaut, also reported that its Lightning node had been swept, though it said little money was held there.

The vulnerability had already been reported to BTCPay by members of the Bitcoin Red Team, a group of developers that began pointing AI models at bitcoin codebases this week and has filed thousands of findings across hundreds of projects since, according to CoinDesk. BTCPay credited Red Team members Craig Raw, Rob Hamilton, Calle, and Evan Kaloudis with responsibly disclosing the issue and helping analyze it. The group's stated reason for publishing findings quickly was that people outside it would arrive at the same bugs, and by the time BTCPay's public warning went out, attackers were already exploiting this one against live servers, per CoinDesk.

BTCPay narrowed the scope after its initial alert, saying its standard on-chain wallets, including hot wallets generated inside BTCPay, are not affected by the credential flaw, according to CoinDesk. The exposure applies specifically to deployments using LND. Funds held inside LND's own on-chain wallet can still be at risk because they sit under the compromised Lightning node, per BTCPay's clarification. BTCPay has not yet published technical details of the vulnerability, saying operators need time to patch. A full postmortem is due in the coming days, according to CoinDesk. The project has not disclosed how many users were hit or how much bitcoin was taken.

The key fact

Attackers drained Lightning nodes behind BTCPay after exploiting a credential-theft vulnerability, prompting BTCPay to order immediate patching or server shutdown.

The Bottom Line

Operators running BTCPay with LND must patch to version 2.4.2 immediately or take servers offline. Watch for BTCPay's postmortem to understand the full scope of affected deployments and total funds drained. The incident underscores the tension between rapid vulnerability disclosure and operator readiness, particularly when exploit code is released before patches ship.

And that's the way it is.

Crypto Cronkite The Crypto Cronkite Desk Ranked, source-checked, and verified by the desk's independent review pass.

Not financial advice. Crypto Cronkite reports events and explains what they may mean. It never tells you to buy or sell anything. Do your own research.