BTCPay restricts remote Lightning access after attackers steal funds

cointelegraphОпубліковано о 2026-08-09Востаннє оновлено о 2026-08-09

Анотація

BTCPay Server has temporarily restricted public remote connections to its integrated Lightning Network nodes after attackers exploited a vulnerability to steal funds. The flaw allowed unauthorized access to the credential files ("macaroons") controlling the Lightning Network Daemon (LND), enabling attackers to take control of nodes and drain funds. The update to version 2.4.2 automatically regenerates these credentials for standard installations. BTCPay advises node operators to check for unauthorized transactions, unexpected channel closures, and balance discrepancies. At least two operators, including Foundation CEO Zach Herbert and Citadel21, have publicly reported losses from their Lightning nodes being swept. This incident follows other recent security issues in the Bitcoin ecosystem, such as a Coldcard hardware wallet flaw.

BTCPay Server has temporarily restricted public remote connections to Lightning Network nodes running Lightning Network Daemon (LND) software after attackers exploited a critical vulnerability to obtain credentials and move funds.

BTCPay said the restriction prevents external wallets such as Zeus from connecting through a BTCPay Server domain or Tor onion address on Docker deployments. BTCPay said Lightning payments can continue and that it plans to restore the remote-access option when it considers it safe.

Version 2.4.2 installs LND version 0.21.1 and automatically regenerates the macaroon credentials on standard BTCPay installations. The project advised operators to check for unauthorized payments, unexpected channel closures, unfamiliar peers and discrepancies in their onchain or Lightning balances.

The BTCPay breach is the latest security incident involving widely used Bitcoin products, following a Coldcard hardware-wallet flaw linked to more than $100 million in confirmed losses. The separate incidents affected software surrounding Bitcoin rather than the network’s underlying protocol.

Update automatically rotates Lightning credentials

BTCPay said the vulnerability allowed an unauthenticated remote attacker to obtain “macaroon” credential files used to control LND, an implementation of the Lightning Network. The project said the exposed credentials could allow attackers to take control of an LND node and move its funds.

According to the project’s security advisory, version 2.4.2 installs LND version 0.21.1 and automatically regenerates macaroon credentials on standard BTCPay installations. It advised operators to check for unauthorized payments, unexpected channel closures, unfamiliar peers and discrepancies between their records and onchain or Lightning balances.

Related: Coldcard exploit pushes July losses to $247M as second-worst month of 2026

BTCPay also said operators exposing LND through their own reverse proxy, Tor service, forwarded port, or another route outside BTCPay must rotate their credentials separately. The project said installing the update does not close access routes managed independently by the operator.

At least two operators publicly reported losses. Foundation CEO Zach Herbert said the hardware-wallet company’s Lightning node was drained overnight. He later clarified that its hot wallet was unaffected, while its Lightning channels were closed and the funds swept.

Bitcoin publication Citadel21 also reported that its Lightning node had been swept. Neither operator disclosed the amount lost.

Magazine: 10 weirdest things ever tokenized... including farts

Пов'язані питання

QWhat action did BTCPay take in response to the attackers exploiting the critical vulnerability?

ABTCPay temporarily restricted public remote connections to Lightning Network nodes running Lightning Network Daemon (LND) software.

QWhat specific items did the security advisory tell operators to check for?

AThe advisory advised operators to check for unauthorized payments, unexpected channel closures, unfamiliar peers, and discrepancies in their onchain or Lightning balances.

QWhat vulnerability did the attackers exploit, and what did it allow them to obtain?

AThe vulnerability allowed an unauthenticated remote attacker to obtain 'macaroon' credential files used to control LND, which is an implementation of the Lightning Network.

QWhat does installing version 2.4.2 of BTCPay Server do automatically for standard installations?

AVersion 2.4.2 installs LND version 0.21.1 and automatically regenerates the macaroon credentials on standard BTCPay installations.

QWhich specific external wallet was mentioned as being prevented from connecting through BTCPay Server?

AThe restriction prevents external wallets such as Zeus from connecting through a BTCPay Server domain or Tor onion address on Docker deployments.

Пов'язані матеріали

Торгівля

Спот
活动图片