Key Takeaways
- A severe security vulnerability in BTCPay Server enabled unauthorized access to Lightning nodes using LND software, resulting in fund theft
- Hackers gained access to sensitive “.macaroon” authentication files, allowing complete control over Lightning Network wallets
- BTCPay Server issued an emergency advisory requiring all users to upgrade to version 2.4.2 or temporarily shut down their systems
- Victims include Foundation, a hardware wallet manufacturer, and Bitcoin media outlet Citadel21, both reporting drained Lightning nodes
- While the Bitcoin Red Team disclosed the vulnerability responsibly, malicious actors had already begun exploiting it when the public alert was issued
A severe security vulnerability in BTCPay Server was actively exploited Friday evening, resulting in the theft of Bitcoin from Lightning Network nodes and prompting emergency warnings for users to either apply critical updates or take their systems offline.
BTCPay Server is a popular open-source platform that enables merchants and enterprises to process Bitcoin payments directly, eliminating the need for third-party custodial services.
The Nature of the Security Breach
The security flaw enabled remote attackers to access “.macaroon” files without authentication. These files serve as authorization credentials that grant applications the ability to communicate with LND Lightning nodes.
LND represents the most popular implementation for operating Lightning Network nodes. With these stolen credential files in hand, malicious actors gained full administrative access to nodes and initiated unauthorized fund transfers.
BTCPay Server acknowledged the theft and issued an immediate directive for all users to install version 2.4.2. Users unable to perform the upgrade were instructed to power down their servers completely until the security patch could be implemented.
The organization has not revealed the number of compromised users or the total value of stolen Bitcoin.
Foundation, a company specializing in hardware wallets, verified that its BTCPay Lightning node was completely drained during the attack. CEO Zach Herbert explained that the attackers forcibly closed the company’s payment channels and transferred all available funds. The company’s on-chain hot wallet remained secure.
Bitcoin-focused media platform Citadel21, operated by pseudonymous figure hodlonaut, also reported having its Lightning node emptied. The publication noted that minimal funds were stored in the node at the time of the breach.
BTCPay Server emphasized that conventional on-chain wallets within the platform were unaffected by this credential vulnerability. However, any Bitcoin stored in LND’s internal on-chain wallet remains vulnerable due to its connection to the compromised node infrastructure.
Recommended Security Measures Post-Update
Following the installation of the security patch, BTCPay Server recommended users regenerate all macaroon credential files and the macaroon database, update authentication tokens connected to Lightning Network backends, and transfer Bitcoin from existing hot wallets within BTCPay before creating fresh wallet instances.
These procedures are designed to invalidate any compromised credentials that attackers may have already obtained.
Discovery and Disclosure Timeline
The vulnerability was identified by the Bitcoin Red Team, a collective of developers who recently launched AI-powered security audits of Bitcoin software repositories. The team privately notified BTCPay Server of the issue. Security researchers Craig Raw, Rob Hamilton, Calle, and Evan Kaloudis received recognition for their responsible disclosure practices.
The team explained their decision to publish findings rapidly stemmed from concerns that independent attackers would inevitably uncover identical vulnerabilities. Unfortunately, active exploitation was already in progress by the time BTCPay Server released its public security advisory.
BTCPay Server has not yet published comprehensive technical documentation regarding the vulnerability. A detailed incident analysis is anticipated within the next several days.


