BTCPay, a widely used open-source payment processor, swiftly advised users running LND (Lightning Network Daemon) – the most prevalent software for operating Lightning nodes – to immediately update to version 2.4.2 or take their servers offline to prevent further losses. While the exact number of affected users and the total amount of Bitcoin stolen remain undisclosed, the exploit has sent ripples through the cryptocurrency community.
The flaw allowed remote, unauthenticated access to ".macaroon" files. These crucial credential files provide software with the necessary permissions to interact with an LND Lightning node. Attackers leveraged this vulnerability to seize control of compromised nodes and subsequently drain their payment channels, moving the contained Bitcoin to their own addresses. Notably, BTCPay's standard on-chain wallets were not affected by this particular breach, indicating a specific targeting of Lightning infrastructure.
Among the confirmed victims are prominent entities in the crypto space. Hardware-wallet manufacturer Foundation reported that its BTCPay Lightning node was drained overnight, with attackers closing channels and sweeping funds. Zach Herbert, Foundation's Chief Executive, confirmed the incident, stating their on-chain hot wallet remained secure. Similarly, Citadel21, a well-known Bitcoin publication helmed by pseudonymous commentator hodlonaut, also announced that its Lightning node had been compromised, though it held a relatively small amount of funds.
This incident adds to what has been described as a challenging week for Bitcoin's software ecosystem. The Lightning Network, built atop the main Bitcoin blockchain, is designed to facilitate instant and low-cost transactions, making it a critical component for merchants accepting Bitcoin payments. The breach underscores the ongoing security challenges inherent in decentralised financial systems and the continuous need for robust protective measures.
The vulnerability had been previously reported to BTCPay by members of the Bitcoin Red Team. This collective of developers has been actively pointing AI models at Bitcoin codebases, identifying thousands of potential issues across hundreds of projects. BTCPay has publicly credited Red Team members, including Craig Raw, for their prior warnings. Both BTCPay and the Bitcoin Red Team are now actively investigating the incident and are preparing a comprehensive postmortem report.
Users of BTCPay Server who operate LND Lightning nodes are urged to take immediate action. Updating to the latest version (2.4.2) is paramount to patching the vulnerability and securing their funds. For those unable to update immediately, taking servers offline is recommended as a precautionary measure to mitigate further risk. This event highlights the critical importance of timely software updates and vigilance within the rapidly evolving landscape of cryptocurrency security.




