Key facts
- Attackers exploited a critical vulnerability in BTCPay Server.
- Funds were stolen from merchant Bitcoin Lightning Network nodes running LND software.
- BTCPay Server has restricted remote connections.
A critical vulnerability in BTCPay Server has led to the draining of merchant Bitcoin Lightning nodes, prompting the platform to restrict remote connections and advise users to update their software. Simultaneously, a volunteer security initiative employing advanced AI models has discovered over a dozen critical vulnerabilities across 150 Bitcoin repositories, affecting wallets, cryptographic libraries, and infrastructure. This AI-driven effort, costing around $20,000, underscores the increasing use of artificial intelligence in identifying security weaknesses within the cryptocurrency sector.

Attackers have exploited a critical vulnerability within BTCPay Server, resulting in the theft of funds from merchant Bitcoin Lightning Network nodes that were running LND software. In response to the exploit, BTCPay Server has taken immediate action by restricting remote connections to mitigate further damage. The platform is strongly urging its users to update their software to the latest version to patch the vulnerability.
In parallel, a volunteer security initiative known as Bitcoin Red Team has leveraged advanced AI models to scan a significant portion of the Bitcoin ecosystem. This initiative has examined 150 Bitcoin repositories, uncovering more than a dozen critical vulnerabilities. These identified flaws span various components, including wallets, cryptographic libraries, and essential infrastructure, indicating a broad impact on the security of Bitcoin-related projects. The AI-driven security audit has cost approximately $20,000 to date.
The discovery of these vulnerabilities by AI highlights a growing trend in the cryptocurrency industry, where artificial intelligence is increasingly being utilized to identify complex security flaws. This proactive approach by initiatives like Bitcoin Red Team aims to bolster the security of core Bitcoin projects before they can be exploited by malicious actors. The findings from both the BTCPay Server exploit and the AI security scan emphasize the ongoing challenges in maintaining robust security within the rapidly evolving cryptocurrency landscape.
Attackers have exploited a critical vulnerability within BTCPay Server, resulting in the theft of funds from merchant Bitcoin Lightning Network nodes that were running LND software. In response to the exploit, BTCPay Server has taken immediate action by restricting remote connections to mitigate further damage. The platform is strongly urging its users to update their software to the latest version to patch the vulnerability.