Attackers have exploited a critical vulnerability in BTCPay Server, leading to the theft of funds from merchant Lightning nodes that use LND software. The flaw allowed remote attackers to gain unauthorized access to ".macaroon" credential files, which are used to authenticate interactions with LND nodes. This enabled attackers to seize control of affected nodes and drain their channels.
Hardware-wallet manufacturer Foundation and bitcoin publication Citadel21 were among the entities that reported their Lightning nodes were compromised. Foundation's CEO, Zach Herbert, confirmed that attackers swept their BTCPay Lightning node, though their on-chain hot wallet remained untouched. Citadel21 also reported its Lightning node was swept, noting minimal funds were held there.
BTCPay Server confirmed that funds were stolen and issued an urgent advisory for users running LND to update to version 2.4.2 immediately or to take their servers offline. The project has not yet disclosed the total number of affected users or the amount of bitcoin stolen. They clarified that BTCPay's standard on-chain wallets, including hot wallets generated within the platform, are not impacted by this specific credential flaw. However, funds held within LND's own on-chain wallet could still be at risk if they are under the control of the compromised Lightning node.
The vulnerability was responsibly disclosed to BTCPay by members of the Bitcoin Red Team, a group of developers who have been actively scanning bitcoin codebases. The team's rationale for rapid disclosure was the belief that others might independently discover the bug, and attackers could exploit it before a public warning. BTCPay credited several Red Team members for their assistance in identifying and analyzing the issue. A full postmortem detailing the vulnerability is expected in the coming days.