EN ▼
Favorites
My Favorites
View All
Market Cap Price 24h%

Disclaimer: Content does not constitute investment advice. Trading involves risks—please invest with caution!

BTCPay server vulnerability allows attackers to steal Lightning nodes...

2026-08-10 12:41:45
Bookmark

What happened to the BTCPay Server lightning node?

BTCPay Server has temporarily restricted public remote connections to Lightning nodes running Lightning Network Daemon (LND) after an attacker used a critical vulnerability to obtain credentials to control affected nodes and transfer funds. The restriction prevents external wallets such as Zeus from connecting through BTCPay Server domain names or Tor onion addresses in Docker deployment environments. BTCPay said the lightning payment feature can still be used, which means the measure is mainly aimed at remote node access rather than completely disabling lightning. The vulnerability exposed a file called "macaroon", which allows access to LND functions. BTCPay points out that an unauthenticated remote attacker can obtain these credentials, which in turn may control nodes and transfer funds without the operator's authorization. At least two operators have so far publicly released loss reports. Zach Herbert, CEO of hardware wallet company Foundation, said its lightning nodes were cleared overnight. He later added that the company's hot money packages had not been affected, but the lightning channel had been closed and funds had been diverted. Bitcoin media Citadel21 also reported that its lightning node was cleared. Neither party disclosed the specific amount of the loss.

How does version 2.4.2 protect operators?

BTCPay Server has released version 2.4.2, which has built-in LND 0.21.1 and automatically regenerates macaroon credentials in a standard BTCPay deployment environment. Credential rotation invalidates previously exposed access files, helping prevent attackers from continuing to use stolen credentials after they are updated by the operator. BTCPay recommends that users check nodes for unauthorized lightning payments, abnormal channel closures, unfamiliar peers, and differences between expected balances and actual funds on the chain or in the lightning network. Automatic credential rotation does not cover all configurations. Credential rotation must be performed separately for operators who expose LND through their own reverse proxy, Tor services, port forwarding, or other access channels outside of BTCPay standard settings. Installing version 2.4.2 does not close remote connections created by administrators independently of BTCPay standard settings. This distinction is critical because operators may think that application updates have eliminated all exposure risks, when in fact separate network rules are still in effect. As a result, BTCPay's response requires users using custom deployments to check both their credentials and how nodes are accessible on the Internet.

Investor Notice

This incident did not affect the underlying Bitcoin network. The risk stems from the software and credentials used by Lightning's infrastructure, which once again emphasizes the difference between protocol security and the security of applications, wallets and node management tools built based on Bitcoin.

Why disable remote lightning access?

Remote access is useful because operators can manage lightning nodes from external tools such as mobile wallets without having to log in directly to the server. However, when credentials that can control nodes can be obtained by attackers, the same feature becomes dangerous. Temporary restrictions on BTCPay have reduced the number of publicly accessible paths, while developers are evaluating when the feature can be safely restored. The project does not say that flash payments themselves need to stop, so merchants and other users can continue to process transactions while restricting remote management access. This response also shows that credential management is particularly important for lightning nodes. Unlike observation-only interfaces, management credentials allow operations involving channels and funds to be performed. If these credentials are stolen, attackers may be able to cause damage in a lightning environment without having to hack into the operator's hardware wallet or obtain mnemonics.

What does this vulnerability mean for Bitcoin security?

Prior to the BTCPay incident, another widely used Bitcoin product-the Coldcard hardware wallet-also experienced security issues that have been confirmed to have caused more than $100 million in losses. The two incidents are independent and affect products surrounding Bitcoin rather than flaws in the Bitcoin consensus or the transaction protocol itself. This distinction is critical for users to assess security risks. The Bitcoin network can continue to function normally, while vulnerabilities in wallets, node software, interfaces or third-party infrastructure may occur, causing theft of individual users. Lightning Network adds another operational layer because users may simultaneously manage hot wallet funds, payment channels, remote interfaces, and online nodes. While this improves payment speed and availability, it also creates more components that need to be properly protected. For BTCPay operators, the top priority is to upgrade to version 2.4.2, check transactions and channel activity, and rotate vouchers for any independently exposed LND connection. Users using custom network configurations also need to confirm that the old path is still accessible after the update. The long-term test will be how BTCPay can restore remote connections without copying the same attack path. Previously, restricting public access, while reducing convenience, blocked a path that attackers had proven to use to steal Lightning funds.

Disclaimer:

All content published on this website, including hyperlinks, related applications, forums, blogs, and other media accounts, originates from third-party platforms and their users. CoinMarketInsight makes no representations or warranties of any kind regarding the website or its content. All blockchain-related data and materials are provided for informational and research purposes only and do not constitute financial, legal, or investment advice. Users and third parties are solely responsible for the content they publish. CoinMarketInsight shall not be liable for any losses arising from the use of this website. You should exercise caution and conduct your own independent research, review, analysis, and verification before making any decisions.

Read Full Article
More News
TOP

TOP