BTCPay Server disclosed an active exploit affecting LND wallets; users must update immediately to v2.4.2.
Security & Exploits ·
BTCPay Server disclosed an active exploit affecting Lightning Network (LND) wallets that can drain funds, prompting an urgent call for users to upgrade to version 2.4.2. The vulnerability poses a direct risk to wallet holders relying on LND infrastructure integrated with BTCPay Server installations.
The exploit targets a specific weakness in how LND wallets interact with BTCPay Server, allowing attackers to drain user balances under certain conditions. The severity of the threat prompted the immediate release of patch version 2.4.2 as a critical security update. Users running earlier versions remain exposed until they apply the fix.
It remains unclear how many BTCPay Server instances are currently affected, whether the exploit has been actively weaponized against users, or the full technical details of the vulnerability mechanism. The disclosure does not specify the attack vector or any timeline for when the flaw was first discovered.