BTCPay restricts remote Lightning access after attackers steal funds

cointelegraphPubblicato 2026-08-09Pubblicato ultima volta 2026-08-09

Introduzione

BTCPay Server has temporarily restricted public remote connections to its integrated Lightning Network nodes after attackers exploited a vulnerability to steal funds. The flaw allowed unauthorized access to the credential files ("macaroons") controlling the Lightning Network Daemon (LND), enabling attackers to take control of nodes and drain funds. The update to version 2.4.2 automatically regenerates these credentials for standard installations. BTCPay advises node operators to check for unauthorized transactions, unexpected channel closures, and balance discrepancies. At least two operators, including Foundation CEO Zach Herbert and Citadel21, have publicly reported losses from their Lightning nodes being swept. This incident follows other recent security issues in the Bitcoin ecosystem, such as a Coldcard hardware wallet flaw.

BTCPay Server has temporarily restricted public remote connections to Lightning Network nodes running Lightning Network Daemon (LND) software after attackers exploited a critical vulnerability to obtain credentials and move funds.

BTCPay said the restriction prevents external wallets such as Zeus from connecting through a BTCPay Server domain or Tor onion address on Docker deployments. BTCPay said Lightning payments can continue and that it plans to restore the remote-access option when it considers it safe.

Version 2.4.2 installs LND version 0.21.1 and automatically regenerates the macaroon credentials on standard BTCPay installations. The project advised operators to check for unauthorized payments, unexpected channel closures, unfamiliar peers and discrepancies in their onchain or Lightning balances.

The BTCPay breach is the latest security incident involving widely used Bitcoin products, following a Coldcard hardware-wallet flaw linked to more than $100 million in confirmed losses. The separate incidents affected software surrounding Bitcoin rather than the network’s underlying protocol.

Update automatically rotates Lightning credentials

BTCPay said the vulnerability allowed an unauthenticated remote attacker to obtain “macaroon” credential files used to control LND, an implementation of the Lightning Network. The project said the exposed credentials could allow attackers to take control of an LND node and move its funds.

According to the project’s security advisory, version 2.4.2 installs LND version 0.21.1 and automatically regenerates macaroon credentials on standard BTCPay installations. It advised operators to check for unauthorized payments, unexpected channel closures, unfamiliar peers and discrepancies between their records and onchain or Lightning balances.

Related: Coldcard exploit pushes July losses to $247M as second-worst month of 2026

BTCPay also said operators exposing LND through their own reverse proxy, Tor service, forwarded port, or another route outside BTCPay must rotate their credentials separately. The project said installing the update does not close access routes managed independently by the operator.

At least two operators publicly reported losses. Foundation CEO Zach Herbert said the hardware-wallet company’s Lightning node was drained overnight. He later clarified that its hot wallet was unaffected, while its Lightning channels were closed and the funds swept.

Bitcoin publication Citadel21 also reported that its Lightning node had been swept. Neither operator disclosed the amount lost.

Magazine: 10 weirdest things ever tokenized... including farts

Domande pertinenti

QWhat action did BTCPay take in response to the attackers exploiting the critical vulnerability?

ABTCPay temporarily restricted public remote connections to Lightning Network nodes running Lightning Network Daemon (LND) software.

QWhat specific items did the security advisory tell operators to check for?

AThe advisory advised operators to check for unauthorized payments, unexpected channel closures, unfamiliar peers, and discrepancies in their onchain or Lightning balances.

QWhat vulnerability did the attackers exploit, and what did it allow them to obtain?

AThe vulnerability allowed an unauthenticated remote attacker to obtain 'macaroon' credential files used to control LND, which is an implementation of the Lightning Network.

QWhat does installing version 2.4.2 of BTCPay Server do automatically for standard installations?

AVersion 2.4.2 installs LND version 0.21.1 and automatically regenerates the macaroon credentials on standard BTCPay installations.

QWhich specific external wallet was mentioned as being prevented from connecting through BTCPay Server?

AThe restriction prevents external wallets such as Zeus from connecting through a BTCPay Server domain or Tor onion address on Docker deployments.

Letture associate

FBI Agent Steals from Within: Millions in Cryptocurrency Stolen by Memorizing Recovery Phrases

A criminal complaint filed in the U.S. District Court for the Eastern District of Virginia details the case of Patrick Steven Yaroch, a former FBI supervisory special agent. Yaroch is accused of using his position to steal nearly $1 million in cryptocurrency from accounts associated with a "foreign adversary" (reportedly Russia) that were under FBI monitoring. He allegedly accessed the accounts' seed phrases from an FBI system, memorized them, and transferred the funds to personal wallets over 10-12 transactions in late 2024 or early 2025. Some stolen assets were held on the Kraken exchange and others were deposited into the Suilend DeFi protocol to earn yield. Despite his senior GS-14 position and high security clearance, Yaroch claimed his actions stemmed from frustration with the FBI's perceived inaction against the monitored accounts. However, evidence from his phone, including ChatGPT conversations from May and June 2026, revealed plans to move to Europe (specifically Portugal) with $1 million and retire early. He booked flights for his family and initiated steps for Portuguese residency. Tormented by guilt, Yaroch voluntarily confessed to the Justice Department and FBI in late July 2026, surrendering the seed phrase and a hardware wallet. He was immediately fired and arrested. He faces charges of interstate transportation of stolen property and receipt of stolen goods. The case highlights vulnerabilities within law enforcement, including excessive access to sensitive data like seed phrases, inadequate internal oversight, and the difficulty of detecting such insider theft on-chain. It echoes past corruption cases, such as those involving agents Carl Force and Shaun Bridges during the Silk Road investigation, where officials misappropriated Bitcoin. The incident underscores that human fallibility remains a critical risk in managing digital assets, even within heavily monitored agencies.

marsbit9 min fa

FBI Agent Steals from Within: Millions in Cryptocurrency Stolen by Memorizing Recovery Phrases

marsbit9 min fa

Inside a Fake Ledger: How a 4G Modem is Secretly Embedded in a Hardware Wallet

In a presentation at Hardwear.io 2026, hardware security expert Joe Grand detailed a sophisticated spy chip discovered inside counterfeit Ledger Nano X hardware wallets. Initially reported in 2021, these tampered devices reached victims through data leaked from Ledger in 2020 and subsequent phishing campaigns. The implanted board connects to the internal SPI bus, passively intercepting data between the Secure Element and the OLED display. Using pattern recognition, it "reads" the seed phrase words displayed during wallet setup or recovery, stores them in its flash memory, and then exfiltrates the data via a built-in 4G modem and eSIM, independent of the victim's computer. To fit the extra hardware, the attackers reduced the battery size and replaced a thermal sensor with a fixed resistor to fake a 100% charge reading. Grand noted this is not an isolated incident, with similar supply-chain attacks previously targeting Trezor devices where compromised firmware generated predictable seed phrases. The researcher plans to intercept and decrypt the chip's cellular traffic to learn more about the attackers. Ledger advises users to purchase devices directly from the manufacturer or authorized resellers, not third-party marketplaces, and to compare devices against official photos. The company is also considering enhanced physical security for future products. The article questions whether Ledger Live's Secure Element authentication would detect such a passive hardware implant and highlights that the core risk lies in the physical supply chain, not just software.

cryptonews.ru34 min fa

Inside a Fake Ledger: How a 4G Modem is Secretly Embedded in a Hardware Wallet

cryptonews.ru34 min fa

Google's Decade-Long AI Power Struggle Concludes, Pichai Gracefully Consolidates Control

A decade of internal AI rivalry at Google has concluded with CEO Sundar Pichai consolidating power through a masterful, bloodless reorganization. The key moves saw Demis Hassabis, DeepMind's visionary founder, step down as CEO of Google DeepMind to become Alphabet's Chief Scientist, focusing on long-term AGI. Concurrently, Google's legendary technical leader Jeff Dean departed with his team to start a new venture, in which Google invested. This restructuring marks the end of a long-standing divide between the research-focused DeepMind and the product-oriented Google Brain. Pichai's strategy, beginning with their 2023 merger under Hassabis, gradually centralized control. While Hassabis gained public acclaim for Gemini's progress and a Nobel Prize, Pichai quietly elevated Koray Kavukcuoglu, a pragmatic engineering veteran, to oversee daily operations. The catalyst was mounting pressure in 2026 as Gemini's development timelines slipped, causing stock declines. Hassabis, more passionate about pure research and his AI drug discovery company Isomorphic Labs, grew weary of the commercial grind. His graceful "promotion" effectively removed him from operational control. Pichai handled both transitions with characteristic finesse: granting Hassabis a prestigious, future-focused role to prevent a defection to rivals (as happened with former DeepMind co-founder Mustafa Suleyman), and investing in Dean's new company to keep his pioneering work within Google's orbit. The outcome is a fundamental shift: control of Google's AI future has passed from brilliant scientist-visionaries to professional managers and engineers like Kavukcuoglu and Pichai himself. It signals Pichai's bet that the AI race has entered an industrial phase won by systemic execution, organizational efficiency, and stable delivery, rather than lone genius. The era of scientists directly managing core AI is over at Google, replaced by a machine-like division of labor where the CEO decides who decides.

marsbit3 h fa

Google's Decade-Long AI Power Struggle Concludes, Pichai Gracefully Consolidates Control

marsbit3 h fa

Trading

Spot
活动图片