Back Finance.Biggo BTCPay Server Emergency Patch Stops Lightning Node Drain; LND Operators Told to ...
Attackers exploited a critical vulnerability in the self-hosted Bitcoin payment processor BTCPay Server late Friday, stealing credentials that control Lightning Network nodes and draining funds from merchants and operators. The project confirmed funds were stolen and issued an emergency release, version 2.4.2, ordering anyone running the affected Lightning Network Daemon (LND) implementation to patch immediately or take their servers offline.
The attack targeted so-called "macaroon" files, the access tokens LND uses to authorize actions on a Lightning node. By obtaining these credential files through an unauthenticated remote exploit, attackers could commandeer nodes, close payment channels and transfer funds without needing to break Bitcoin's cryptography or steal a seed phrase.
Hardware wallet maker Foundation and Bitcoin publication Citadel21 both confirmed their BTCPay Lightning nodes were drained in the incident. Foundation said its on-chain hot wallet was not reached. The total amount of Bitcoin stolen and the number of victims remained undisclosed as of Saturday, as the project withheld full technical details to give operators time to patch.
"If you are unable to update right away, turn off your BTCPay Server to prevent unauthorized access until you can update," the BTCPay team said in its advisory, a blunt warning that signaled the severity of an actively exploited flaw.
Bitcoin's price showed little reaction to the infrastructure breach, trading up 0.61% at $64,986.0 as of 04:54 ET (08:54 GMT) Saturday, according to Investing.com data. The broader crypto market mirrored the muted response, with Ether (ETH) rising 0.32% to $1,916.82, XRP (XRP) adding 0.41% to $1.0353, and Solana (SOL) climbing 2.16% to $74.78.
The Crypto Fear and Greed Index sat at 30, indicating "Fear" but not the kind of panic that would suggest a market-wide crisis tied to the exploit.
The confirmed risk is narrow but severe. Only operators running BTCPay Server versions earlier than 2.4.2 with LND-based Lightning deployments are affected. BTCPay's standard on-chain wallets, including hot wallets generated within the software, were not compromised by the vulnerability.
However, funds held in an LND node's on-chain wallet may still be at risk if control of the node was compromised, BTCPay warned. Other Lightning implementations face no specific exposure, though the project still strongly recommends updating older BTCPay Server versions regardless of configuration.
What Operators Must Do
Affected users must update to BTCPay Server 2.4.2, which also upgrades LND to version 0.21.1. Integrators are advised to update NBXplorer to version 2.6.10 alongside it. Anyone unable to patch immediately should shut down the server entirely.
Once patched, operators should conduct a full security review: check for unauthorized payments, unexpected channel closures, unfamiliar peers, and discrepancies between expected and actual node balances. The update regenerates LND macaroons, but users who expose their node through reverse proxies, forwarded ports or Tor services should review those access routes and rotate credentials where necessary.
"Installing the patch closes the known vulnerability, but it cannot determine whether credentials were copied while the server was still exposed," BTCPay noted in its guidance.
A Pattern of Infrastructure Failures
The BTCPay incident arrives during an awkward week for Bitcoin holders already rattled by a separate security failure involving Coldcard hardware wallets, where confirmed losses reached at least $116 million. The two incidents involve different products and there is no indication they are connected, but their proximity has reignited debate over the responsibilities that come with holding Bitcoin directly.
Neither incident indicates Bitcoin's base layer was compromised. Instead, they highlight how many components matter once users take direct responsibility for their coins. A seed phrase may be perfectly safe while software or server credentials create another route to funds. For operators running their own infrastructure, hardware security is only part of the job; network exposure, access permissions and software maintenance carry equal weight.
The Coldcard exploit was framed as a tooling issue rather than a weakness in Bitcoin's base layer, and the BTCPay breach follows the same pattern. This is a compromise of self-hosted server deployments, not a failure of the Lightning Network protocol or Bitcoin itself.
BTCPay has not yet published a technical postmortem describing the exact vulnerability path and affected version range. No authoritative public total for the number of compromised servers or the amount of Bitcoin stolen was available as of Saturday. Until a postmortem is published, the precise mechanism that allowed attackers to obtain macaroon files remains an informed inference rather than a fully documented root cause.
Containment signals to watch include a published BTCPay technical postmortem, confirmation from Foundation and Citadel21 on final loss figures, and a block-explorer-linked tally that would let the ecosystem measure total funds moved.
Separate Bitcoin Fork Risk
Bitcoin holders also face an unrelated risk from the proposed BIP-110 fork, which could begin around block 961,632 this weekend. The proposal would temporarily restrict non-payment data stored in Bitcoin transactions. Miner signaling was near 2.6% on Friday, far below the 55% threshold required for activation, yet computers running BIP-110 software are programmed to reject non-signaling blocks once the activation height is reached, potentially creating a minority chain.
If a split occurs, holders would initially have equal balances on both chains. Selling the forked coins could expose real BTC to replay attacks, as the same signed transaction may be valid on both networks. Developer Kevin Loaec advised holders who cannot separate the balances to leave them untouched.
Custody Debate Intensifies
After two very different security incidents in the same week, the practical question for Bitcoin holders is less finding a custody method with zero risk and more understanding exactly where control sits. Which device, credential or service can move the funds? Who controls it? And if something is exposed, how quickly can that access be replaced or revoked?
Some holders may respond by moving more responsibility to a custodian or gaining Bitcoin exposure through an ETF. That removes many of the technical tasks faced by an individual operator, but leaves the assets dependent on third-party custody and the protections surrounding it.
For affected BTCPay users, the immediate priorities are simpler: update the server, inspect the LND node and deal with any credentials that may have been exposed. The project's open-source model allows independent developers to review code and fixes, but self-hosting also leaves individual operators responsible for keeping software updated and securing their own servers.
Once added, BigGo Finance appears first in Google Top Stories, so you get the broadest, most up-to-the-minute, and most comprehensive global financial news first.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
