EN ▼
Favorites
My Favorites
View All
Market Cap Price 24h%

Disclaimer: Content does not constitute investment advice. Trading involves risks—please invest with caution!

BTCPay Server suspends remote access to lightning nodes due to security breach

2026-08-10 00:40:50
Bookmark

Core Points

BTCPay Server has turned off external remote access on its Lightning network nodes after discovering that a serious security vulnerability was exploited.

The hacker obtained the "macaroon" authentication file that controls the LND node, allowing it to transfer funds without authorization.

The emergency patch (version 2.4.2) fixes the vulnerability and automatically refreshes credentials under the default configuration.

Foundation CEO Zach Herbert confirmed that his organization's lightning node has been completely emptied.

Citadel21, a bitcoin-focused media, also confirmed that its lightning node was hacked, and neither party disclosed the specific amount of the loss.

Patch details and functions

In response to a serious security vulnerability that resulted in the theft of funds from multiple operators, BTCPay Server has temporarily interrupted public remote connections to Lightning network nodes. This security incident specifically targets infrastructure running Lightning Network Daemon (LND) software. The attacker took advantage of this security vulnerability by obtaining a "macaroon" authentication file-a special credential that grants operational control over the LND node. Once these credentials are obtained, malicious actors can move funds without restrictions.

This protection prevents external wallet applications such as Zeus from establishing connections through the BTCPay Server domain name or Tor onion addresses based on Docker-based deployments. Despite this limitation, BTCPay confirms that Lightning Internet Payment will still operate normally and plans to restore remote access when security conditions permit.

BTCPay urgently deployed version 2.4.2 to respond to this security incident. This release integrates LND version 0.21.1 and automates the regeneration of macaroon credentials for standard deployment configurations. Node operators who set up LND routing by custom reverse proxies, stand-alone Tor services, or configuring port forwarding outside of BTCPay standard settings must manually rotate their authentication credentials. The patch does not automatically protect the operator's own configured access paths.

BTCPay has recommended that all node operators conduct a thorough security audit, including checking transaction history to detect suspicious transactions, verifying channel closure activity, identifying unknown network peers, and checking balance records for on-chain and Lightning network accounts.

Confirmed victim

Foundation CEO Zach Herbert publicly stated that his organization's lightning node was completely emptied during the night. He later clarified that the company's hot wallet infrastructure remained secure and unaffected. The attack method involves the forced closure of channels and subsequent systematic withdrawal of funds. Bitcoin-focused media Citadel21 has also been confirmed to be a victim of the attack, reporting that its lightning nodes have been completely cleared. Both affected parties declined to disclose the specific amount of their losses. The full scope of the intrusion, including the total number of operators damaged, has not yet been determined.

The security incident follows the discovery of another vulnerability in Coldcard's hardware wallet that resulted in recorded losses of more than $100 million. Both security incidents targeted the Bitcoin ecosystem infrastructure and supporting software, rather than undermining Bitcoin's core protocols or blockchain network. BTCPay has made it clear that the two security incidents are not related to each other. Still, successive infrastructure vulnerabilities have increased security awareness and vigilance among the Bitcoin operator community.

BTCPay promises to reactivate remote access after completing comprehensive security verification, but has not yet announced a specific recovery timetable. All operators running affected systems are strongly recommended to immediately deploy security updates and conduct a comprehensive review of node activity to identify potential unauthorized access or signs of intrusion.

Disclaimer:

All content published on this website, including hyperlinks, related applications, forums, blogs, and other media accounts, originates from third-party platforms and their users. CoinMarketInsight makes no representations or warranties of any kind regarding the website or its content. All blockchain-related data and materials are provided for informational and research purposes only and do not constitute financial, legal, or investment advice. Users and third parties are solely responsible for the content they publish. CoinMarketInsight shall not be liable for any losses arising from the use of this website. You should exercise caution and conduct your own independent research, review, analysis, and verification before making any decisions.

Read Full Article
More News
TOP

TOP