EN ▼
Favorites
My Favorites
View All
Market Cap Price 24h%

Disclaimer: Content does not constitute investment advice. Trading involves risks—please invest with caution!

BTCPay server vulnerability caused LND node funds to be stolen, restricting lightning network access

2026-08-11 00:41:42
Bookmark

BTCPay Server temporarily restricts remote access, confirms vulnerability leads to credential theft and loss of funds.

The open source Bitcoin payment processor BTCPay Server has temporarily restricted public remote access to Lightning network nodes running LND after confirming that an attacker used a serious vulnerability to steal credentials and transfer funds. The vulnerability affects all BTCPay Server versions prior to version 2.4.2, including release candidates for 2.4.2. Attackers were able to obtain LND's "macaroon" files, which authorized control of Lightning nodes and their funds.

BTCPay has confirmed that users were affected and funds were stolen, but did not disclose the total amount of the loss or the number of operators damaged. While the operator continues to upgrade, the project has not yet disclosed complete technical details.

Version 2.4.2 temporarily removes public access to the LND API in Docker deployments. This means that external wallets such as Zeus cannot currently connect to LND through the BTCPay Server domain name or Tor onion address. Normal lightning payments can still continue, and BTCPay said it will resume remote access after it deems it safe to set up.

BTCPay urges LND users to immediately update

BTCPay Server 2.4.2 to upgrade standard deployments to LND 0.21.1 and automatically regenerate macaroon credentials. Operators should then check their nodes for unauthorized payments, unexpected channel closures, unfamiliar peers, and unexplained differences in on-chain or lightning balances.

Users who expose LND through their own reverse proxy, Tor service, port forwarding, or other external BTCPay paths must rotate their credentials separately because BTCPay updates do not close independently managed access paths. Operators that cannot update immediately have been asked to take affected LND deployments offline.

The GitHub release of 2.4.2 also tightened Greenfield API security, including a fix for bypassing TOTP dual-factor authentication through basic authentication. Basic authentication is now disabled by default five minutes after account creation unless the user re-enables it. BTCPay has not released enough information to determine whether this is the exact way for attackers to obtain LND credentials.

Foundation and Citadel21 report that node funds have been emptied

At least two operators have publicly reported losses. Zach Herbert, CEO of hardware wallet company Foundation, said that its lightning node funds were cleared, channels were closed and funds were swept away, but its hot wallet on its BTCPay chain was not affected. Bitcoin media Citadel21 also reported that its lightning node funds were swept away. Neither disclosed the amount of the loss.

BTCPay emphasized that its standard on-chain wallets (including hot money packages) are not affected by LND certificate issues, but funds in LND's own on-chain wallets may still be at risk. The project promises to release a more detailed post-mortem analysis report in the next few days.

Disclaimer:

All content published on this website, including hyperlinks, related applications, forums, blogs, and other media accounts, originates from third-party platforms and their users. CoinMarketInsight makes no representations or warranties of any kind regarding the website or its content. All blockchain-related data and materials are provided for informational and research purposes only and do not constitute financial, legal, or investment advice. Users and third parties are solely responsible for the content they publish. CoinMarketInsight shall not be liable for any losses arising from the use of this website. You should exercise caution and conduct your own independent research, review, analysis, and verification before making any decisions.

Read Full Article
More News
TOP

TOP