Home Nft BTCPay Server Vulnerability Exploited, Draining Merchant Lightning Nodes

BTCPay Server Vulnerability Exploited, Draining Merchant Lightning Nodes

by Sebastian Tucker


A critical vulnerability in BTCPay Server is being actively exploited, allowing attackers to drain Bitcoin from Lightning Network nodes used by merchants and other businesses.

BTCPay Server confirmed the attacks late Friday, warning operators running LND, the most widely used software for operating Lightning nodes, to immediately update to version 2.4.2 or take vulnerable servers offline.

The project has not disclosed how many users were affected or how much Bitcoin was stolen. However, at least two organizations have publicly confirmed losses.

The incident adds another security concern to a difficult week for Bitcoin infrastructure, after researchers uncovered thousands of vulnerabilities across Bitcoin-related projects through large-scale, AI-assisted code reviews.

BTCPay Server vulnerability exploited (Source: X)BTCPay Server vulnerability exploited (Source: X)

BTCPay Server vulnerability exploited (Source: X)

How the Vulnerability Worked

BTCPay Server is an open-source, self-hosted Bitcoin payment processor that allows merchants to accept Bitcoin without relying on centralized payment providers. Many businesses connect BTCPay to the Lightning Network to process faster and cheaper payments.

The vulnerability affected BTCPay installations connected to LND.

Attackers were able to remotely access .macaroon files containing credentials used to authorize actions on an LND Lightning node. These credentials can grant software permission to interact with the node, including managing channels and moving funds.

Once attackers obtained the credentials, they could effectively take control of the affected Lightning node. According to BTCPay, the attacks it reviewed targeted these credential files and used them to close Lightning channels and sweep Bitcoin from compromised nodes.

The flaw was particularly dangerous because it did not require an attacker to first authenticate with the affected server.

BTCPay has not yet released the technical details of the vulnerability. The project said operators need time to patch their systems before a full disclosure. A detailed postmortem is expected in the coming days.

Foundation Among Victims

Bitcoin hardware-wallet manufacturer Foundation was among the organizations affected.

Zach Herbert, Foundation’s CEO, said attackers drained the company’s Lightning node overnight. The attackers closed its channels and swept the funds held by the node.

However, Foundation’s separate BTCPay on-chain hot wallet was not affected.

Bitcoin publication Citadel21, operated by pseudonymous commentator hodlonaut, also reported that its Lightning node had been swept. The publication said the node contained only a small amount of Bitcoin.

These reports provide an early indication of the exploit’s reach, although the overall scale remains unclear. BTCPay has not provided a figure for the number of compromised servers or the total value of stolen funds.

Foundation Among VictimsFoundation Among Victims

Foundation Among Victims

Not All BTCPay Wallets Are Affected

BTCPay later clarified that the vulnerability does not affect its standard on-chain wallets, including hot wallets generated directly within BTCPay Server.

The exposure is specifically associated with deployments using LND.

That distinction is important because a merchant may operate several different components through BTCPay. Lightning funds are controlled by the LND node, while an on-chain wallet generated within BTCPay can operate separately.

However, Bitcoin held in the LND wallet can still be at risk because it is controlled by the compromised node. Operators therefore should not assume their funds are safe simply because they are not currently locked in Lightning channels.

The incident highlights the security risks of connecting multiple self-hosted components. A vulnerability in the payment server can potentially expose credentials used to control an underlying wallet or Lightning node.

Bitcoin Red Team Found the Flaw

The vulnerability was discovered by members of the Bitcoin Red Team, a group of developers conducting security reviews of Bitcoin-related software.

BTCPay credited Craig Raw, Rob Hamilton, Calle and Evan Kaloudis with reporting the vulnerability and helping investigate the incident.

The discovery came during a broader initiative in which the group has been using artificial intelligence to examine Bitcoin codebases for security weaknesses. The effort has generated thousands of findings across hundreds of projects.

The BTCPay incident also demonstrates the difficult balance between vulnerability disclosure and active exploitation.

According to the researchers, their decision to publish findings quickly is based partly on the belief that other security researchers or attackers could independently discover the same vulnerabilities. In this case, however, attackers were already exploiting the BTCPay flaw against live servers by the time the project’s public warning was issued.

That creates a difficult situation for open-source projects, where vulnerabilities can be discovered simultaneously by defenders and malicious actors.

LND Operators Urged to Act

BTCPay has urged users running LND to update to version 2.4.2 immediately. Operators who cannot patch should take their BTCPay servers offline.

Users should also check their Lightning nodes for unexpected channel closures, unauthorized transactions or other suspicious activity. Because credentials may have been exposed, operators should follow BTCPay’s additional remediation guidance as it becomes available.

The incident is a reminder that self-hosted Bitcoin infrastructure offers greater control but also places security responsibility directly on users.

For merchants relying on Lightning for everyday payments, a vulnerability in the software connecting their payment system to their node can quickly turn into a direct financial loss.

With the number of affected servers and total stolen Bitcoin still unknown, the full impact of the BTCPay exploit may only become clear after the project’s promised postmortem. For now, operators using BTCPay with LND face a simple priority: patch immediately or take the server offline.



Source link

You may also like

Follow us on:

© 2025 decentralnewshub.xyz. All rights reserved.

Sign up and save

Sign up and you’ll always be the first to know about any promotions, discounts or giveaways.

Subscribe my Newsletter for new blog posts, tips & new photos. Let's stay updated!