A critical flaw in BTCPay Server let attackers drain Bitcoin Lightning nodes late on Friday by exposing the credentials that protect them. BTCPay told operators running LND to update to version 2.4.2 immediately or take their servers offline, and confirmed its standard on-chain wallets were not affected. Hardware-wallet maker Foundation and bitcoin publication Citadel21 are among the confirmed victims.
Attackers drained Lightning nodes running behind BTCPay Server late on Friday, exploiting a critical vulnerability that exposed the credentials protecting them. BTCPay confirmed funds were stolen and told anyone running LND, the most widely used Lightning node software, to update immediately to version 2.4.2 or take the server offline.
A credential flaw, not a wallet breach
The bug let an unauthenticated remote attacker obtain LND's ".macaroon" files, credentials that can then be used to take control of a node and move its funds. BTCPay narrowed the scope after its initial alert, saying its standard on-chain wallets, including hot wallets generated inside BTCPay, are not affected by the credential flaw. The exposure applies specifically to LND deployments, so funds sitting inside LND's own on-chain wallet can still be at risk because they sit under the compromised node.
According to Crypto Briefing, the credentials were also unusually persistent: the macaroons remained valid even after operators applied earlier software updates, so a manual credential refresh was needed on top of the patch. BTCPay released version 2.4.2 alongside guidance to upgrade its NBXplorer backend to version 2.6.10. This vulnerability was separate from a prior authentication bug the project had already patched days earlier.
Foundation and Citadel21 among the victims
Foundation, the hardware-wallet maker, was among those hit. Chief Executive Zach Herbert said attackers drained the company's BTCPay Lightning node overnight, closing its channels and sweeping the funds, while its on-chain hot wallet stayed untouched. Citadel21, the bitcoin publication run by hodlonaut, also reported that its Lightning node had been swept, though it said little money was held there. BTCPay has not disclosed how many users were hit or how much bitcoin was taken.
The flaw had already been reported to BTCPay by members of the Bitcoin Red Team, a group BTCPay credited — Craig Raw, Rob Hamilton, Calle and Evan Kaloudis — for responsibly disclosing and helping analyze the issue. The group began pointing AI models at bitcoin codebases this week and has filed thousands of findings across hundreds of projects since, yet attackers were already exploiting this bug against live servers by the time BTCPay's public warning went out. BTCPay has not yet published technical details, saying operators need time to patch, and a full postmortem is due in the coming days.
Sources: CoinDesk, Crypto Briefing
Trading involves risk.