All NewsEducationTV
Equities & FundsCrypto & Digital AssetsAI & TechnologyBusiness & CorporateUS Politics & PolicyGeopolitics & Global RiskMacro, Rates & FXCommodities & EnergyEuropean Politics & MarketsAsia-PacificReal Estate & Property
Story archiveAll categories
← All Stories

Bitcoin Lightning nodes drained in BTCPay Server exploit

Created at 8 Aug · 7:51 AM1 source↑ Market-relevant
IN SHORT

Attackers exploited a critical vulnerability in BTCPay Server, targeting Lightning nodes running LND software to steal funds by accessing credential files. Urgent updates or server shutdowns are advised.

✉Newsletter

PiQ Daily

Pick your topics. Get only what matters, on your cadence.

Key Numbers

2.4.2BTCPay Server LND version for update

Who's Involved

BTCPay Server
Platform affected by critical vulnerability
LND
Lightning node software targeted by exploit
Foundation
Hardware-wallet maker and victim of the exploit
Citadel21
Bitcoin publication and victim of the exploit
Bitcoin Red Team
Developers who reported and helped analyze the issue
Bitcoin Lightning nodes drained in BTCPay Server exploit

↳ Why This Matters

This exploit highlights ongoing security challenges within the bitcoin ecosystem's secondary layers, potentially eroding trust in the Lightning Network's infrastructure for merchants and users.

Key facts

  • A critical vulnerability in BTCPay Server allowed attackers to steal funds from Lightning nodes.
  • The exploit targeted LND ".macaroon" credential files, granting attackers control of nodes.
  • Hardware-wallet maker Foundation and publication Citadel21 were among the victims.
  • BTCPay has urged users to update to version 2.4.2 or disconnect their servers.
  • Standard BTCPay on-chain wallets were not affected by this specific vulnerability.
  • Attackers have exploited a critical vulnerability in BTCPay Server, leading to the theft of funds from merchant Lightning nodes that use LND software. The flaw allowed remote attackers to gain unauthorized access to ".macaroon" credential files, which are used to authenticate interactions with LND nodes. This enabled attackers to seize control of affected nodes and drain their channels.

    Hardware-wallet manufacturer Foundation and bitcoin publication Citadel21 were among the entities that reported their Lightning nodes were compromised. Foundation's CEO, Zach Herbert, confirmed that attackers swept their BTCPay Lightning node, though their on-chain hot wallet remained untouched. Citadel21 also reported its Lightning node was swept, noting minimal funds were held there.

    BTCPay Server confirmed that funds were stolen and issued an urgent advisory for users running LND to update to version 2.4.2 immediately or to take their servers offline. The project has not yet disclosed the total number of affected users or the amount of bitcoin stolen. They clarified that BTCPay's standard on-chain wallets, including hot wallets generated within the platform, are not impacted by this specific credential flaw. However, funds held within LND's own on-chain wallet could still be at risk if they are under the control of the compromised Lightning node.

    The vulnerability was responsibly disclosed to BTCPay by members of the Bitcoin Red Team, a group of developers who have been actively scanning bitcoin codebases. The team's rationale for rapid disclosure was the belief that others might independently discover the bug, and attackers could exploit it before a public warning. BTCPay credited several Red Team members for their assistance in identifying and analyzing the issue. A full postmortem detailing the vulnerability is expected in the coming days.

    Frequently asked questions

    A critical vulnerability in BTCPay Server allowed attackers to access LND ".macaroon" credential files.

    Lightning nodes running LND software behind BTCPay Server were affected.

    Attackers drained Lightning channels. Standard BTCPay on-chain wallets were not impacted, but funds within LND's on-chain wallet under the compromised node could be at risk.

    Users should update to BTCPay Server version 2.4.2 or take their servers offline immediately.

    What Happens Next

    01BTCPay Server to publish a full postmortem on the incident.
    02Users are advised to update to version 2.4.2 or take servers offline.

    Get the newsletter.

    Pick the topics you actually care about. We'll email when there's news worth your time, on the cadence you choose. Cancel any time from your account.

    Cadence
    CME Headlines
    • Product Modification Summary: Amendments to the Strike Price Listing Schedule for all Hourly Event Contract Swaps on Ether — Effective August 10, 2026
      6 Aug · 7:45 PM
    • Amendments to the Strike Price Listing Schedule for all Hourly Event Contract Swaps on Ether
      5 Aug · 7:15 PM

    How It Developed

    Attackers exploited a vulnerability in BTCPay Server to steal funds from Lightning nodes.
    The flaw allowed unauthenticated access to LND ".macaroon" credential files.
    Victims including Foundation and Citadel21 reported their Lightning nodes were swept.
    BTCPay confirmed funds were stolen and advised users to update to version 2.4.2 or take servers offline.
    BTCPay stated that its standard on-chain wallets were not impacted.

    Sources

    T1
    Another bitcoin infrastructure exploit hits, this time draining merchant Lightning nodesCoinDesk

    Related Stories

    Bitcoin Payment Processor BTCPay Server Under Active Attack Due to Critical Flaw
    7 Aug · 8:11 PM
    Bitcoin ETFs See $800 Million Inflow After Coldcard Exploit
    7 Aug · 4:06 PM
    Bitcoin holders risk losing BTC from BIP-110 fork without replay protection
    8 Aug · 2:36 AM
    Bybit sues North Korea, Lazarus Group over $1.5B hack, secures asset freeze
    7 Aug · 4:41 PM
    Hackers Use BNB Chain to Spread Malware Via Fake CAPTCHAs
    7 Aug · 4:41 PM