Bitcoin Lightning nodes drained in BTCPay Server exploit
window 24h
IN SHORT
A volunteer security initiative employing AI has discovered over a dozen critical vulnerabilities across 150 Bitcoin repositories, affecting wallets, cryptographic libraries, and infrastructure. This AI-driven effort, costing around $20,000, underscores the increasing use of artificial intelligence in identifying security weaknesses in the crypto space. Separately, attackers exploited a critical vulnerability in BTCPay Server, targeting Lightning nodes running LND software by accessing credential files to drain funds, prompting urgent calls for updates or server shutdowns.
✉Newsletter
PiQ Daily
Pick your topics. Get only what matters, on your cadence.
Key Numbers
150Bitcoin repositories scanned
$20,000cost of AI security effort
Who's Involved
Bitcoin
cryptocurrency project with scanned repositories
AI
technology used for security scanning
BTCPay Server
software with a critical vulnerability
Lightning nodes
targets of BTCPay Server exploit
LND software
software used by targeted Lightning nodes
1 / 2
Key facts
A volunteer security initiative used AI to scan 150 Bitcoin repositories.
Over a dozen critical vulnerabilities were identified in wallets, libraries, and infrastructure.
The AI security effort has cost approximately $20,000 so far.
Attackers exploited a critical vulnerability in BTCPay Server.
The exploit targeted Lightning nodes running LND software.
Attackers accessed credential files to drain funds from nodes.
Urgent updates or server shutdowns are advised for BTCPay Server users.
A volunteer security initiative, leveraging advanced AI models, has identified more than a dozen critical vulnerabilities within 150 Bitcoin repositories. These exploits span across wallets, cryptographic libraries, and core infrastructure, highlighting the growing capability of AI in uncovering security flaws within the cryptocurrency industry. The initiative has cost approximately $20,000 to date.
In a related development, attackers have exploited a critical vulnerability present in BTCPay Server. This exploit specifically targets Bitcoin Lightning nodes that are running LND software. The attackers gain access to credential files, which then allows them to drain funds from these nodes. Users are strongly advised to apply urgent updates to their BTCPay Server instances or to shut down their servers entirely to prevent further losses.
The AI-driven security scan demonstrates a proactive approach to identifying potential weaknesses before they can be exploited maliciously. The breadth of vulnerabilities found suggests a systemic challenge in securing the complex ecosystem of Bitcoin and its related technologies. The BTCPay Server incident serves as a stark reminder of the immediate and tangible financial risks associated with unpatched vulnerabilities in widely used cryptocurrency infrastructure.
↳ Why This Matters
A volunteer security initiative, leveraging advanced AI models, has identified more than a dozen critical vulnerabilities within 150 Bitcoin repositories. These exploits span across wallets, cryptographic libraries, and core infrastructure, highlighting the growing capability of AI in uncovering security flaws within the cryptocurrency industry. The initiative has cost approximately $20,000 to date.
Frequently asked questions
A critical vulnerability in BTCPay Server allowed attackers to access LND ".macaroon" credential files.
Lightning nodes running LND software behind BTCPay Server were affected.
Attackers drained Lightning channels. Standard BTCPay on-chain wallets were not impacted, but funds within LND's on-chain wallet under the compromised node could be at risk.
Users should update to BTCPay Server version 2.4.2 or take their servers offline immediately.
What Happens Next
01BTCPay Server to publish a full postmortem on the incident.
02Users are advised to update to version 2.4.2 or take servers offline.
Get the newsletter.
Pick the topics you actually care about. We'll email when there's news worth your time, on the cadence you choose. Cancel any time from your account.