Another Bitcoin infrastructure exploit hits, this time draining Lightning payment servers
BTCPay told users running LND to update immediately or take servers offline after attackers stole credentials that can control Lightning wallets and move funds.
Make preferred on
Share this article
Summary
- Attackers exploited a critical vulnerability in BTCPay Server to steal funds from Lightning nodes running LND, prompting urgent calls to update to version 2.4.2 or take servers offline.
- The flaw allowed unauthenticated access to LND “.macaroon” credential files, enabling attackers to seize control of affected Lightning nodes and drain their channels, though BTCPay’s standard on-chain wallets were not impacted.
- Victims including hardware-wallet maker Foundation and bitcoin publication Citadel21 reported their Lightning nodes were swept, as BTCPay and the Bitcoin Red Team investigate and prepare a full postmortem on the incident.

