BTCPay Server vulnerability: Merchants lightning nodes have been stolen, developers urgently call for updates.
Open source Bitcoin payment processor BTCPay Server is urging node operators to immediately update or shut down the system because a vulnerability that has been actively exploited allows attackers to steal funds from lightning nodes operated by merchants. The vulnerability mainly targets infrastructure hosted by merchants, which was originally used to accept Bitcoin payments, but has now become a risk point for financial loss.
Impact of vulnerability on merchant lightning nodes
The core of this incident is the Bitcoin payment infrastructure associated with the lightning network. Lightning Network is a layer 2 protocol that allows merchants to quickly settle small bitcoin payments. BTCPay Server is managed by the operator itself, not through a third party, and is the core of the affected system. Maintainers inform operators that they must immediately update or close the instance due to a vulnerability that is being actively exploited. The so-called "fund theft" means that an attacker transfers bitcoins from hot wallets or lightning nodes connected to a merchant without authorization.
This type of risk is specifically targeted at merchant nodes because such wallets must remain online to process incoming payments. This always-on status makes it different from other authority-based theft in the cryptocurrency space, such as the theft of packaged bitcoins in certain incidents.
Why merchant operating infrastructure was exposed
The vulnerability is an implementation issue with the BTCPay Server software itself, not a flaw in the Lightning Network Protocol itself. This difference is important: the vulnerability lies in the commercial-facing application layer, and the details are explained in the project's 2.4.2 security bulletin. Merchant environments are at greater risk than ordinary users because they run connected hot wallets and lightning channels that must remain fully funded and accessible to receive payments. Ordinary users can store coins in cold wallets, but merchant nodes cannot.
Currently, the root cause and total damage of the vulnerability are still under investigation. Existing research has not yet confirmed the exact amount of the loss or the number of merchants affected, so any broader speculation should be cautious. This model of stealing real-time balances through vulnerabilities is similar to some past cross-chain incidents.
What to do next for node operators?
Maintainers have only two options: update to a fixed version, or take the instance offline before it becomes impossible to update. Operators who cannot upgrade immediately should shut down the system rather than leaving vulnerable nodes exposed to risk. The fix is included in version 2.4.2, and the version history is recorded in the project's public change log. After completing the remediation, operators should check recent channel activity and wallet transactions to confirm whether there are unauthorized operations.
For merchants running bitcoin payment tracks on a large scale, this incident reminds us that self-managed infrastructure carries operational risks in addition to price fluctuations. Operators should pay attention to subsequent disclosures from the BTCPay Server team to confirm the full scope of impact and any additional mitigation measures.

Exchange Ranking
Top Exchanges
24h Volume Ranking
Popularity Ranking
Exchange BTC Balance
Proof of Reserves
Decentralized Exchanges
Funding Rate
Funding Heatmap
Liquidation Data
Max Pain
Long/Short Ratio
Whale L/S Ratio
Binance/Okex/Huobi L/S
Bitfinex Margin L/S
ETF Tracker
Solana ETF
XRP ETF
Hong Kong ETF
Bitcoin Treasuries
Crypto Reversal
Ethereum Reserves
HyperLiquid Wallet Analysis
Hyperliquid Whale Watch
Large Transactions
On-chain Movement
Bitcoin ROI
Stablecoin Market Cap
Options Analysis
News
Articles
Economic Calendar
Features
Wallet
Contract Calculator
Security
Collections
Watchlist
Following
BTC