BTCPay Server temporarily restricts remote access, confirms vulnerability leads to credential theft and loss of funds.
The open source Bitcoin payment processor BTCPay Server has temporarily restricted public remote access to Lightning network nodes running LND after confirming that an attacker used a serious vulnerability to steal credentials and transfer funds. The vulnerability affects all BTCPay Server versions prior to version 2.4.2, including release candidates for 2.4.2. Attackers were able to obtain LND's "macaroon" files, which authorized control of Lightning nodes and their funds.
BTCPay has confirmed that users were affected and funds were stolen, but did not disclose the total amount of the loss or the number of operators damaged. While the operator continues to upgrade, the project has not yet disclosed complete technical details.
Version 2.4.2 temporarily removes public access to the LND API in Docker deployments. This means that external wallets such as Zeus cannot currently connect to LND through the BTCPay Server domain name or Tor onion address. Normal lightning payments can still continue, and BTCPay said it will resume remote access after it deems it safe to set up.
BTCPay urges LND users to immediately update
BTCPay Server 2.4.2 to upgrade standard deployments to LND 0.21.1 and automatically regenerate macaroon credentials. Operators should then check their nodes for unauthorized payments, unexpected channel closures, unfamiliar peers, and unexplained differences in on-chain or lightning balances.
Users who expose LND through their own reverse proxy, Tor service, port forwarding, or other external BTCPay paths must rotate their credentials separately because BTCPay updates do not close independently managed access paths. Operators that cannot update immediately have been asked to take affected LND deployments offline.
The GitHub release of 2.4.2 also tightened Greenfield API security, including a fix for bypassing TOTP dual-factor authentication through basic authentication. Basic authentication is now disabled by default five minutes after account creation unless the user re-enables it. BTCPay has not released enough information to determine whether this is the exact way for attackers to obtain LND credentials.
Foundation and Citadel21 report that node funds have been emptied
At least two operators have publicly reported losses. Zach Herbert, CEO of hardware wallet company Foundation, said that its lightning node funds were cleared, channels were closed and funds were swept away, but its hot wallet on its BTCPay chain was not affected. Bitcoin media Citadel21 also reported that its lightning node funds were swept away. Neither disclosed the amount of the loss.
BTCPay emphasized that its standard on-chain wallets (including hot money packages) are not affected by LND certificate issues, but funds in LND's own on-chain wallets may still be at risk. The project promises to release a more detailed post-mortem analysis report in the next few days.

Exchange Ranking
Top Exchanges
24h Volume Ranking
Popularity Ranking
Exchange BTC Balance
Proof of Reserves
Decentralized Exchanges
Funding Rate
Funding Heatmap
Liquidation Data
Max Pain
Long/Short Ratio
Whale L/S Ratio
Binance/Okex/Huobi L/S
Bitfinex Margin L/S
ETF Tracker
Solana ETF
XRP ETF
Hong Kong ETF
Bitcoin Treasuries
Crypto Reversal
Ethereum Reserves
HyperLiquid Wallet Analysis
Hyperliquid Whale Watch
Large Transactions
On-chain Movement
Bitcoin ROI
Stablecoin Market Cap
Options Analysis
News
Articles
Economic Calendar
Features
Wallet
Contract Calculator
Security
Collections
Watchlist
Following
BTC