BTCPay Server exploit drains Lightning nodes running LND
Security & Exploits ·
A critical flaw in BTCPay Server let attackers pull credential files and empty merchant Lightning channels, pushing the project to demand emergency patching.
Attackers took advantage of an unauthenticated access point in BTCPay Server to seize ".macaroon" files, the credentials LND uses to authorize control over a Lightning node, and used them to seize channels and move the bitcoin inside, according to Coindesk. The sweep took place late on a Friday, and BTCPay confirmed the theft in a post on X, telling every operator running LND, the most common Lightning node software, to upgrade to version 2.4.2 immediately or pull their servers offline, per the announcement. The project has not said how many operators were affected or how much bitcoin was taken.
The exposure is narrower than it first appeared: BTCPay later clarified that its own on-chain wallets, including hot wallets built directly into the platform, were not touched by the credential bug. Risk is confined to setups running LND, where funds sitting in LND's own on-chain wallet remain exposed because they are tied to the same compromised node.
Hardware-wallet maker Foundation was among those hit, with its chief executive saying the company's BTCPay-linked Lightning node was drained overnight as channels were closed and swept, while its separate on-chain hot wallet was left alone. The bitcoin publication Citadel21, run by a pseudonymous commentator, said its own Lightning node was also swept, though it held little money at the time.
The bug had already been flagged to BTCPay by contributors tied to the Bitcoin Red Team, a group that has spent the week running AI models against bitcoin-related codebases and logging large numbers of findings across many projects, a pattern also tracked by leviathan.news. BTCPay credited several named Red Team members with responsibly disclosing and helping analyze the issue, but by the time its public warning went out, attackers were already exploiting the flaw against live servers, underscoring how quickly disclosed bugs can be weaponized once posted.
BTCPay has withheld technical details of the vulnerability to give operators time to patch, with a full postmortem promised in the coming days. Unresolved questions include the total number of nodes and the total bitcoin amount affected, along with whether further exploitation occurs before broader adoption of version 2.4.2.