Finst

BTCPay Flaw Hits Lightning Nodes and Disrupts Bitcoin Payments

Attackers were able to take over LND nodes through .macaroon credentials, with Foundation and Citadel21 among those reporting losses. BTCPay says to update to 2.4.2 right away.

BTCPay Flaw Hits Lightning Nodes and Disrupts Bitcoin Payments

Key Takeaways

  • A critical flaw in BTCPay Server allowed attackers to drain Lightning nodes running LND by stealing .macaroon credentials.
  • BTCPay urged LND users to upgrade to version 2.4.2 immediately or shut their server down, and confirmed that funds were stolen.
  • Foundation and Citadel21 were among the users reporting losses, while BTCPay said standard on-chain wallets were not impacted.

A serious vulnerability in BTCPay Server has once again put the security of Bitcoin payment infrastructure in the spotlight. Attackers were able to empty Lightning nodes connected to BTCPay after obtaining credentials used to access LND, the most common software for running a Lightning node.

Late Friday, BTCPay told users running LND to either upgrade to version 2.4.2 immediately or take their server offline. The project also confirmed that funds were stolen, but it did not disclose how many users were affected or how much Bitcoin was lost.

How the Attack Worked

BTCPay said an unauthenticated attacker was able to remotely obtain .macaroon files, which are the credentials software uses to talk to an LND node. In the incidents the team reviewed, those files were the entry point. Once the attacker had them, they could take control of the node and move funds.

One of the affected users was hardware wallet maker Foundation. CEO Zach Herbert said attackers drained the company’s BTCPay Lightning node overnight, closed channels, and siphoned off the funds. He said BTCPay’s on-chain hot wallet was not affected.

Citadel21, the Bitcoin publication from pseudonymous commentator hodlonaut, also said its Lightning node was drained. According to the report, the node did not hold much money.

Why This Matters More Broadly

BTCPay Server is an open-source, self-hosted Bitcoin payment processor that lets merchants accept Bitcoin directly on-chain and over Lightning. Because many users run their own wallets and nodes, a bug in the software can quickly spill over into real operational funds and payment activity.

That makes an incident like this especially sensitive at a time when other self-hosted storage tools are also under strain. In a recent attack on hardware wallets, a flaw in key management showed how fast a small mistake can turn into real losses, as seen in an active Bitcoin wallet exploit.

The timing adds another layer of concern. The vulnerability had already been flagged by members of the Bitcoin Red Team, a group of developers that uses AI models to look for bugs in Bitcoin codebases and submitted thousands of reports across hundreds of projects over the past week. BTCPay thanked Craig Raw, Rob Hamilton, Calle, and Evan Kaloudis for reporting the issue responsibly and helping analyze it.

What Operators Need to Know Now

BTCPay later clarified that its standard on-chain wallets, including hot wallets created inside BTCPay, were not affected by this credential issue. The risk is limited to installations using LND, although funds in LND’s on-chain wallet can still be exposed because they sit under the compromised Lightning node.

The company has not yet released technical details about the bug, saying operators need time to patch first. A full postmortem is expected in the coming days. For European crypto users and merchants, the episode is a reminder that risk does not only live in smart contracts or exchanges, but also in the software stack that supports Bitcoin payments and node management.


Disclaimer: This content is for informational purposes only and does not constitute financial, investment, legal, or tax advice. The information provided may be incomplete, inaccurate, or outdated and should not be relied upon as such. Nothing on this website should be considered a recommendation to buy, sell, or hold any cryptocurrency. Investing in crypto-assets involves risk of loss.