BTCPay Server warns of active exploit draining funds via stolen Lightning credentials
Security & Exploits ·
An emergency advisory covers all versions before 2.4.2, with attackers already using compromised LND macaroon credentials to steal user funds.
BTCPay Server disclosed that every version prior to 2.4.2 carries a critical vulnerability that attackers are actively exploiting to steal funds through compromised LND macaroon credentials, according to an advisory posted on X. The company is urging operators to upgrade immediately to BTCPay Server 2.4.2 and LND 0.21.1 to close the hole.
The attack path runs through macaroon credentials, the authentication tokens LND uses to grant access to a node's wallet functions. Once an attacker obtains a valid macaroon from an unpatched instance, they can apparently issue commands that move funds out of the affected wallet without further authorization, which is why the company is treating the flaw as urgent enough for an emergency notice rather than a routine update.
Because BTCPay Server is widely self-hosted by merchants and individuals running their own Lightning infrastructure, the exposure is not confined to a single centralized platform; each unpatched instance represents an independent target until its operator applies the fix. Corroborating reports describe merchant Bitcoin wallets being compromised through the same stolen Lightning Network credentials, with the company offering a $190K bounty tied to the incident.
Supporters have separately organized a recovery bounty of up to 3 BTC aimed at retrieving lost funds, a figure repeated across multiple accounts of the exploit, as noted by The Block. Some of that coverage includes speculation that artificial intelligence may have been used to locate the vulnerability, though this remains unconfirmed.
What remains unclear is how many instances have already been compromised, the total value of funds stolen, and whether the bounty efforts have led to any recovery. It is also not established whether the vulnerability was discovered through automated or AI-assisted means, or through conventional security research. Users running BTCPay Server or LND on affected versions have not been given a timeline in the material for how long the exploit was active before the advisory was issued.