EN ▼
Favorites
My Favorites
View All
Market Cap Price 24h%

Disclaimer: Content does not constitute investment advice. Trading involves risks—please invest with caution!

BTCPay restricts remote lightning access after attackers steal funds

2026-08-10 00:42:33
Bookmark

BTCPay Server temporarily restricts remote connections to Lightning Network

BTCPay Server has recently encountered a security vulnerability that attackers used to obtain user credentials and transfer funds. To this end, BTCPay temporarily restricted public remote connections to Lightning Network nodes running Lightning Network Daemon (LND) software. BTCPay said the restriction will prevent external wallets such as Zeus from connecting through the BTCPay Server domain name or Tor onion address in Docker deployment environments. At the same time, BTCPay pointed out that the Lightning Internet payment feature can still be used normally and plans to restore remote access options after confirming security.

Version 2.4.2 has LND version 0.21.1 installed and macaroon credentials are automatically regenerated in a standard BTCPay installation. The project party recommends that operators check for unauthorized payments, unexpected channel closures, unfamiliar nodes, and abnormalities in on-chain or lightning network balances.

This BTCPay security incident is another recent incident involving widely used Bitcoin products. Previously, Coldcard hardware wallet vulnerability has been confirmed to have caused more than $100 million in losses. These independent events affect bitcoin-related software, not the underlying protocol of the bitcoin network itself.

Update auto-rotating Lightning Network credentials

BTCPay indicates that the vulnerability allows an unauthenticated remote attacker to obtain a "macaroon" credential file used to control LND, an implementation of Lightning Network. The project party pointed out that compromised credentials could allow attackers to take control of LND nodes and transfer their funds.

According to the project security bulletin, version 2.4.2 has LND version 0.21.1 installed and macaroon credentials are automatically regenerated in standard BTCPay installations. The project party recommends that operators check for unauthorized payments, unexpected channel closures, unfamiliar nodes, and differences between their own records and on-chain or Lightning network balances.

BTCPay also stated that if an operator exposes LND through its own reverse proxy, Tor service, port forwarding, or other non-BTCPay means, credentials must be rotated separately. The project party emphasized that installing updates will not close the access channel independently managed by the operator.

At least two operators have so far publicly reported losses. Zach Herbert, CEO of hardware wallet company Foundation, said his company's lightning nodes were emptied overnight. He later clarified that hot wallets were not affected, but the lightning channel was closed and funds were diverted. Bitcoin media Citadel21 also reported that its lightning node funds were swept away. Neither operator disclosed the specific amount of the loss.

Disclaimer:

All content published on this website, including hyperlinks, related applications, forums, blogs, and other media accounts, originates from third-party platforms and their users. CoinMarketInsight makes no representations or warranties of any kind regarding the website or its content. All blockchain-related data and materials are provided for informational and research purposes only and do not constitute financial, legal, or investment advice. Users and third parties are solely responsible for the content they publish. CoinMarketInsight shall not be liable for any losses arising from the use of this website. You should exercise caution and conduct your own independent research, review, analysis, and verification before making any decisions.

Read Full Article
More News
TOP

TOP