
BTCPay has advised LND users to patch their systems immediately or take their servers offline after hackers obtained credentials that could give them control over Lightning wallets and allow them to steal funds.
Bitcoin’s infrastructure is facing another security setback, with the latest incident affecting merchants that process BTC payments through the Lightning Network, a system designed to enable faster and cheaper transactions.
Attackers drained funds from Lightning nodes running through BTCPay Server on Friday after exploiting a critical security flaw that exposed protected credentials, according to the BTCPay team.
The project confirmed that funds had been stolen and urged operators using LND, the most widely adopted Lightning node software, to upgrade to version 2.4.2 or shut down their servers until they can be secured.
BTCPay has not said how many operators were affected or provided an estimate of the total bitcoin stolen.
The vulnerability enabled remote attackers without authentication to obtain “.macaroon” files. These files serve as credentials that authorize software to interact with LND nodes. Attackers who obtained them could potentially take control of the nodes and transfer their funds.
Foundation, a hardware wallet manufacturer, was among the reported victims. CEO Zach Herbert said the company’s BTCPay Lightning node was drained overnight, with its channels closed and funds swept out. Its separate on-chain hot wallet was not affected.
Citadel21, a Bitcoin publication operated by pseudonymous commentator hodlonaut, also said its Lightning node was swept, although only a limited amount of bitcoin was stored there.
The security issue had previously been disclosed to BTCPay by members of the Bitcoin Red Team, a developer group that has been using AI models to examine Bitcoin-related code. The group has reported thousands of vulnerabilities across hundreds of projects.
BTCPay acknowledged Craig Raw, Rob Hamilton, Calle, and Evan Kaloudis for responsibly reporting the vulnerability and assisting with the investigation.
The researchers said they published their findings quickly because similar vulnerabilities could be discovered by others. In this case, attackers had already begun targeting active servers by the time BTCPay issued its public warning.
BTCPay later clarified that its standard on-chain wallets, including hot wallets created through the platform, are not vulnerable to the credential leak.
The exposure is limited to deployments running LND. However, assets held in LND’s own on-chain wallet could also be vulnerable because they are connected to the affected Lightning node.
BTCPay has withheld detailed technical information while users have time to apply the necessary fixes. The project said a full postmortem will be released in the coming days.





