What happened to the BTCPay Server lightning node?
BTCPay Server has temporarily restricted public remote connections to Lightning nodes running Lightning Network Daemon (LND) after an attacker used a critical vulnerability to obtain credentials to control affected nodes and transfer funds. The restriction prevents external wallets such as Zeus from connecting through BTCPay Server domain names or Tor onion addresses in Docker deployment environments. BTCPay said the lightning payment feature can still be used, which means the measure is mainly aimed at remote node access rather than completely disabling lightning. The vulnerability exposed a file called "macaroon", which allows access to LND functions. BTCPay points out that an unauthenticated remote attacker can obtain these credentials, which in turn may control nodes and transfer funds without the operator's authorization. At least two operators have so far publicly released loss reports. Zach Herbert, CEO of hardware wallet company Foundation, said its lightning nodes were cleared overnight. He later added that the company's hot money packages had not been affected, but the lightning channel had been closed and funds had been diverted. Bitcoin media Citadel21 also reported that its lightning node was cleared. Neither party disclosed the specific amount of the loss.
How does version 2.4.2 protect operators?
BTCPay Server has released version 2.4.2, which has built-in LND 0.21.1 and automatically regenerates macaroon credentials in a standard BTCPay deployment environment. Credential rotation invalidates previously exposed access files, helping prevent attackers from continuing to use stolen credentials after they are updated by the operator. BTCPay recommends that users check nodes for unauthorized lightning payments, abnormal channel closures, unfamiliar peers, and differences between expected balances and actual funds on the chain or in the lightning network. Automatic credential rotation does not cover all configurations. Credential rotation must be performed separately for operators who expose LND through their own reverse proxy, Tor services, port forwarding, or other access channels outside of BTCPay standard settings. Installing version 2.4.2 does not close remote connections created by administrators independently of BTCPay standard settings. This distinction is critical because operators may think that application updates have eliminated all exposure risks, when in fact separate network rules are still in effect. As a result, BTCPay's response requires users using custom deployments to check both their credentials and how nodes are accessible on the Internet.
Investor Notice
This incident did not affect the underlying Bitcoin network. The risk stems from the software and credentials used by Lightning's infrastructure, which once again emphasizes the difference between protocol security and the security of applications, wallets and node management tools built based on Bitcoin.
Why disable remote lightning access?
Remote access is useful because operators can manage lightning nodes from external tools such as mobile wallets without having to log in directly to the server. However, when credentials that can control nodes can be obtained by attackers, the same feature becomes dangerous. Temporary restrictions on BTCPay have reduced the number of publicly accessible paths, while developers are evaluating when the feature can be safely restored. The project does not say that flash payments themselves need to stop, so merchants and other users can continue to process transactions while restricting remote management access. This response also shows that credential management is particularly important for lightning nodes. Unlike observation-only interfaces, management credentials allow operations involving channels and funds to be performed. If these credentials are stolen, attackers may be able to cause damage in a lightning environment without having to hack into the operator's hardware wallet or obtain mnemonics.
What does this vulnerability mean for Bitcoin security?
Prior to the BTCPay incident, another widely used Bitcoin product-the Coldcard hardware wallet-also experienced security issues that have been confirmed to have caused more than $100 million in losses. The two incidents are independent and affect products surrounding Bitcoin rather than flaws in the Bitcoin consensus or the transaction protocol itself. This distinction is critical for users to assess security risks. The Bitcoin network can continue to function normally, while vulnerabilities in wallets, node software, interfaces or third-party infrastructure may occur, causing theft of individual users. Lightning Network adds another operational layer because users may simultaneously manage hot wallet funds, payment channels, remote interfaces, and online nodes. While this improves payment speed and availability, it also creates more components that need to be properly protected. For BTCPay operators, the top priority is to upgrade to version 2.4.2, check transactions and channel activity, and rotate vouchers for any independently exposed LND connection. Users using custom network configurations also need to confirm that the old path is still accessible after the update. The long-term test will be how BTCPay can restore remote connections without copying the same attack path. Previously, restricting public access, while reducing convenience, blocked a path that attackers had proven to use to steal Lightning funds.

Exchange Ranking
Top Exchanges
24h Volume Ranking
Popularity Ranking
Exchange BTC Balance
Proof of Reserves
Decentralized Exchanges
Funding Rate
Funding Heatmap
Liquidation Data
Max Pain
Long/Short Ratio
Whale L/S Ratio
Binance/Okex/Huobi L/S
Bitfinex Margin L/S
ETF Tracker
Solana ETF
XRP ETF
Hong Kong ETF
Bitcoin Treasuries
Crypto Reversal
Ethereum Reserves
HyperLiquid Wallet Analysis
Hyperliquid Whale Watch
Large Transactions
On-chain Movement
Bitcoin ROI
Stablecoin Market Cap
Options Analysis
News
Articles
Economic Calendar
Features
Wallet
Contract Calculator
Security
Collections
Watchlist
Following
BTC