BTCPay Server temporarily restricts remote connections to Lightning Network
BTCPay Server has recently encountered a security vulnerability that attackers used to obtain user credentials and transfer funds. To this end, BTCPay temporarily restricted public remote connections to Lightning Network nodes running Lightning Network Daemon (LND) software. BTCPay said the restriction will prevent external wallets such as Zeus from connecting through the BTCPay Server domain name or Tor onion address in Docker deployment environments. At the same time, BTCPay pointed out that the Lightning Internet payment feature can still be used normally and plans to restore remote access options after confirming security.
Version 2.4.2 has LND version 0.21.1 installed and macaroon credentials are automatically regenerated in a standard BTCPay installation. The project party recommends that operators check for unauthorized payments, unexpected channel closures, unfamiliar nodes, and abnormalities in on-chain or lightning network balances.
This BTCPay security incident is another recent incident involving widely used Bitcoin products. Previously, Coldcard hardware wallet vulnerability has been confirmed to have caused more than $100 million in losses. These independent events affect bitcoin-related software, not the underlying protocol of the bitcoin network itself.
Update auto-rotating Lightning Network credentials
BTCPay indicates that the vulnerability allows an unauthenticated remote attacker to obtain a "macaroon" credential file used to control LND, an implementation of Lightning Network. The project party pointed out that compromised credentials could allow attackers to take control of LND nodes and transfer their funds.
According to the project security bulletin, version 2.4.2 has LND version 0.21.1 installed and macaroon credentials are automatically regenerated in standard BTCPay installations. The project party recommends that operators check for unauthorized payments, unexpected channel closures, unfamiliar nodes, and differences between their own records and on-chain or Lightning network balances.
BTCPay also stated that if an operator exposes LND through its own reverse proxy, Tor service, port forwarding, or other non-BTCPay means, credentials must be rotated separately. The project party emphasized that installing updates will not close the access channel independently managed by the operator.
At least two operators have so far publicly reported losses. Zach Herbert, CEO of hardware wallet company Foundation, said his company's lightning nodes were emptied overnight. He later clarified that hot wallets were not affected, but the lightning channel was closed and funds were diverted. Bitcoin media Citadel21 also reported that its lightning node funds were swept away. Neither operator disclosed the specific amount of the loss.

Exchange Ranking
Top Exchanges
24h Volume Ranking
Popularity Ranking
Exchange BTC Balance
Proof of Reserves
Decentralized Exchanges
Funding Rate
Funding Heatmap
Liquidation Data
Max Pain
Long/Short Ratio
Whale L/S Ratio
Binance/Okex/Huobi L/S
Bitfinex Margin L/S
ETF Tracker
Solana ETF
XRP ETF
Hong Kong ETF
Bitcoin Treasuries
Crypto Reversal
Ethereum Reserves
HyperLiquid Wallet Analysis
Hyperliquid Whale Watch
Large Transactions
On-chain Movement
Bitcoin ROI
Stablecoin Market Cap
Options Analysis
News
Articles
Economic Calendar
Features
Wallet
Contract Calculator
Security
Collections
Watchlist
Following
BTC