Morning Edition ·
Markets SAN FRANCISCO

Lightning Node Wallets Drained in BTCPay Server Security Scare

A critical BTCPay Server vulnerability let attackers hijack and drain Lightning Network nodes running LND, though the platform's standard on-chain wallets were unaffected as a patch went out this week.

SHARE X f in

BTCPay Server, widely used open-source software that lets merchants accept bitcoin payments without a third-party processor, confirmed this week that a critical, actively exploited vulnerability had allowed attackers to drain funds from Lightning Network nodes run through the platform. The company said its standard on-chain wallets were not affected, but operators who had connected an LND-based Lightning node saw their channels emptied.

The Lightning Network is a separate payment layer built on top of Bitcoin that enables near-instant, low-fee transfers, and LND — short for Lightning Network Daemon — is the most widely deployed software for running a Lightning node. According to CoinDesk's reporting, the flaw let an unauthenticated remote attacker retrieve a node's ".macaroon" file — a credential that grants full permission to control the node — and use it to close channels and sweep the underlying bitcoin before operators could react.

Confirmed Losses, Undisclosed Total

BTCPay Server has not said how many users were affected or how much bitcoin was taken in total, but at least two operators have confirmed losses: hardware-wallet maker Foundation and the bitcoin publication Citadel21. Foundation's chief executive, Zach Herbert, said attackers drained the company's BTCPay Lightning node overnight, closing its channels and sweeping the funds, while its separate on-chain hot wallet was unaffected — a distinction that lines up with the company's broader guidance that only Lightning-connected setups were exposed, according to Cointelegraph.

Drained the company's BTCPay Lightning node overnight, closing its channels and sweeping the funds.

Zach Herbert, CEO, Foundation

BTCPay credited the discovery to a group of independent researchers known as the Bitcoin Red Team, including Sparrow Wallet developer Craig Raw and ZEUS wallet developer Evan Kaloudis, who disclosed the bug before it went public. The project pushed out version 2.4.2, which upgrades bundled LND software and automatically regenerates macaroon credentials on standard installations, and it began restricting remote Lightning connections on its Docker-based deployments by default.

Developers cautioned that patching alone does not undo the damage: updating closes the door to new attacks but does not invalidate credentials already stolen from a server that ran a vulnerable version. BTCPay urged any operator who had not yet updated to take their node offline immediately, revoke macaroons at the node level so the underlying signing key is destroyed rather than just the credential files, and move funds out of any exposed on-chain hot wallet as a precaution. The company said a full technical postmortem would follow once enough operators had patched.

SHARE THIS ARTICLE X Facebook LinkedIn Copy link
Sofia Marino · Venture & Technology Economy Correspondent

Covers venture capital and the business of technology for UBStandard — funding cycles, startups and the economics of innovation.

[email protected]
Related coverage Front page →