News
Platform news and market context
News
Platform news and market context
BTCPay Halts Remote Lightning Access After Critical Flaw Allows Attackers to Steal Funds
BTCPay Server has disabled remote connections to LND nodes after a vulnerability let attackers obtain credentials and drain funds. While a patch is available and some victims like Foundation and Citadel21 have come forward, the total losses remain unknown.

Following the exploitation of a critical vulnerability that allowed attackers to steal funds, BTCPay Server has implemented a temporary suspension of public remote access for Lightning Network nodes utilizing Lightning Network Daemon (LND) software.
According to a statement from BTCPay, this measure blocks external wallets, including Zeus, from establishing connections via a BTCPay Server domain or a Tor onion address within Docker environments. The project confirmed that Lightning payments remain operational and intends to reactivate the remote-access feature once it is deemed secure.
Vulnerability and Attacker Actions
BTCPay explained that the security flaw permitted a remote, unauthenticated attacker to acquire the “macaroon” credential files that are necessary for controlling LND, a specific implementation of the Lightning Network. With these exposed credentials, attackers could seize control of an LND node and proceed to drain its funds, the project noted.
While Foundation and Citadel21 have confirmed their Lightning nodes were drained, the full scope of the attack, including the total amount stolen and the complete number of victims, is not yet known.
Security Patch and Operator Guidance
The project's security advisory details that a patch, version 2.4.2, not only installs LND version 0.21.1 but also triggers an automatic regeneration of macaroon credentials for standard BTCPay installations. Operators have been advised to meticulously inspect their nodes for any signs of compromise, such as unauthorized payments, sudden channel closures, connections to unfamiliar peers, or any inconsistencies in their on-chain or Lightning balances.
For users with custom configurations, BTCPay specified that operators who expose their LND nodes through methods like a personal reverse proxy, Tor service, or forwarded port must perform a separate, manual rotation of their credentials. The project emphasized that simply installing the update will not secure these access routes that are managed independently by the node operator.
Confirmed Victims and Industry Context
Public reports of financial losses have emerged from at least two operators. Zach Herbert, the CEO of the hardware-wallet company Foundation, said his firm's Lightning node was emptied of its funds overnight. In a subsequent clarification, Herbert confirmed that Foundation's hot wallet remained secure, but its Lightning channels had been forcibly closed and the associated funds stolen.
Similarly, the Bitcoin-focused publication Citadel21 reported that its own Lightning node was also swept. The value of the funds lost was not disclosed by either of the affected operators.
This security breach at BTCPay marks another recent incident affecting popular Bitcoin-related products, coming after a vulnerability in Coldcard hardware wallets was connected to confirmed losses exceeding $100 million. It is important to note that both of these separate events impacted the software ecosystem built around Bitcoin, not the fundamental protocol of the network itself.
Discussion about this post
No comment yet
Be the first to share your opinion!