TLDR
- Attackers exploited a critical flaw in BTCPay Server, stealing funds from Lightning nodes running LND software
- The vulnerability exposed “.macaroon” credential files, giving attackers control over Lightning wallets
- BTCPay Server urged all users to update immediately to version 2.4.2 or take servers offline
- Hardware wallet maker Foundation and Bitcoin publication Citadel21 confirmed their nodes were drained
- The Bitcoin Red Team responsibly disclosed the flaw, but attackers were already exploiting it by the time the public warning went out
Attackers exploited a critical security flaw in BTCPay Server late Friday, draining Bitcoin funds from Lightning Network nodes and forcing an urgent call for users to update or shut down their servers.
There is a critical vulnerability being actively exploited on BTCPay Server, which can result in the loss of funds.
Please update your BTCPayServer to 2.4.2 by going to Admin Dashboard -> Server -> Maintenance -> Update & verify the 2.4.2 version string in the footer.
If you…
— BTCPay Server (@BtcpayServer) August 7, 2026
BTCPay Server is an open-source Bitcoin payment processor used by merchants and businesses to accept Bitcoin payments without relying on third-party custodians.
What Was Exploited
The vulnerability allowed unauthenticated remote attackers to steal “.macaroon” files. These are credential files that give software permission to interact with an LND Lightning node.
LND is the most widely used software for running a Lightning node. Once attackers had those files, they could take control of a node and move funds out.
BTCPay confirmed funds were stolen and told users to update immediately to version 2.4.2. Those who could not update were told to shut their servers down entirely until the patch could be applied.
The team has not disclosed how many users were affected or the total amount of Bitcoin taken.
Hardware wallet company Foundation confirmed its BTCPay Lightning node was drained overnight. Its CEO, Zach Herbert, said attackers closed the company’s channels and swept the funds. Its on-chain hot wallet was not affected.
Bitcoin publication Citadel21, run by the pseudonymous commentator hodlonaut, also confirmed its Lightning node was swept. It said little money was held there at the time.
BTCPay clarified that standard on-chain wallets inside BTCPay are not affected by the credential flaw. However, funds held inside LND’s own on-chain wallet remain at risk because they sit under the compromised node.
Security Steps Advised After Patching
After updating, BTCPay advised users to refresh all macaroon files and the macaroon database, rotate authentication strings used with Lightning Network backends, and move Bitcoin from any hot wallets created within BTCPay before generating new wallets.
These steps are meant to cancel out any credentials that may already be in the hands of attackers.
Who Found the Flaw
The Bitcoin Red Team, a group of developers that began running AI models against Bitcoin codebases this week, privately reported the vulnerability to BTCPay. Researchers Craig Raw, Rob Hamilton, Calle, and Evan Kaloudis were credited with the responsible disclosure.
The group said it published findings quickly because outside attackers would likely discover the same bugs independently. By the time BTCPay’s public warning went out, exploitation was already underway.
BTCPay has not yet released technical details of the vulnerability. A full postmortem is expected in the coming days.






Be the first to comment