EN ▼
Favorites
My Favorites
View All
Market Cap Price 24h%

Disclaimer: Content does not constitute investment advice. Trading involves risks—please invest with caution!

BTCPay Server is under attack! Lightning nodes were ransacked

2026-08-10 00:41:16
Bookmark

BTCPayServer security vulnerability causes Lightning node funds to be stolen

The security vulnerability in BTCPayServer has evolved into an attack on Lightning node funds. The platform temporarily restricted remote Lightning access after attackers accessed nodes and transferred funds. Both Foundation and Citadel21 said they suffered losses in the attack, but the total amount stolen is unclear.

It is reported that an attacker obtained the "macaroon" credentials needed to control nodes using Lightning Network Daemon (LND) software. These credentials can allow attackers to take full control of nodes and transfer funds.

BTCPay Server stated that remote access options will be reopened after security is confirmed. Lightning payment features are not affected by restrictions and can continue to operate normally.

Why does BTCPay Server restrict remote access?

The measure taken by BTCPay is to temporarily prevent external wallets (such as Zeus) during Docker installations from connecting to Lightning nodes through the BTCPay Server domain name or Tor ion address.

The project noted that the attack was able to obtain LND credentials, which could be used to control nodes and transfer funds.

The 2.4.2 update released by BTCPay upgrades LND to version 0.21.1. In standard BTCPay installations, updates automatically refresh macaroon credentials.

Node operators should check balances

BTCPay Server recommends that operators check their own nodes after updates, paying particular attention to the following behaviors:

Unauthorized payments
Unexpected closed channels
Unknown Peering Connection
Inconsistent with Lightning balances on the chain

These checks are critical to determining whether an attacker has visited a node.

Users who use custom access paths need to pay extra attention

For operators that are not included in BTCPay Server but use their own reverse proxy, Tor service, or port forwarding, they need to operate separately.

BTCPay points out that these users need to refresh their credentials themselves. The 2.4.2 update will not close access paths managed by operators independently of BTCPay. Therefore, simply installing updates does not automatically protect access channels outside BTCPay.

Foundation and Citadel21 report losses

At least two operators suffered losses in the attack and have publicly stated.

Zach Herbert, CEO of Bitcoin hardware wallet company Foundation, said that the company's Lightning node was cleared overnight. Herbert later added that hot wallets were not affected, but the Lightning channel was closed and funds in the channel were swept away by attackers.

Bitcoin content platform Citadel21 also announced that its Lightning node has been cleared. Neither agency disclosed the specific amount of money lost in the attack.

The overall scale of the attack is unclear

So far, at least two operators have confirmed losses due to the attack. However, the total number of operators affected and the total amount of stolen funds are still unknown.

This incident is the latest in a series of recent security issues targeting products in the Bitcoin ecosystem. Some people believe that this is a security issue for Bitcoin's surrounding software and services, rather than a problem with Bitcoin's core protocol itself.

Previously, vulnerabilities in Coldcard's hardware wallet have also caused millions of dollars in Bitcoin losses.

This content is based on general market data and does not constitute investment advice. It is recommended that you study on your own.

Disclaimer:

All content published on this website, including hyperlinks, related applications, forums, blogs, and other media accounts, originates from third-party platforms and their users. CoinMarketInsight makes no representations or warranties of any kind regarding the website or its content. All blockchain-related data and materials are provided for informational and research purposes only and do not constitute financial, legal, or investment advice. Users and third parties are solely responsible for the content they publish. CoinMarketInsight shall not be liable for any losses arising from the use of this website. You should exercise caution and conduct your own independent research, review, analysis, and verification before making any decisions.

Read Full Article
More News
TOP

TOP