Critical BTCPay Server Vulnerability Exploited, Draining Lightning Node Funds

Critical BTCPay Server Vulnerability Exploited, Draining Lightning Node Funds

First seen 8 Aug 2026, 15:04 UTC CryptobriefingUk.Finance.Yahoo 76% similarity 69.9

Article Content

Browse articles
ThreatCluster

On August 7, 2026, a critical vulnerability in BTCPay Server was exploited, allowing attackers to drain funds from Lightning nodes. The flaw involved unauthorized access to Lightning node credentials, specifically 'macaroons', which persisted after software updates. Prominent victims included hardware wallet maker Foundation and Bitcoin publication Citadel21, both confirming losses from their Lightning channels. BTCPay Server issued an urgent alert, urging operators to update to version 2.4.2 or shut down their servers. The attack highlights the challenges of maintaining security in self-hosted Bitcoin infrastructures. A detailed analysis of the exploit is expected in the coming days. The incident comes amid increased scrutiny of Bitcoin infrastructure security.

Key Points: • A critical vulnerability in BTCPay Server allowed unauthorized access to Lightning node credentials. • Prominent victims include hardware wallet maker Foundation and Bitcoin publication Citadel21. • BTCPay Server has urged operators to update immediately to prevent further losses.

ThreatCluster AI How this analysis works

Timeline

2026-08-07
BTCPay Server vulnerability exploited
Attackers exploited a flaw allowing them to drain funds from Lightning nodes, affecting notable users.
Cryptobriefing
2026-08-07
BTCPay Server issues urgent security alert
The project urged all operators to update to version 2.4.2 or shut down their servers to prevent losses.
Uk.Finance.Yahoo
2026-08-08
Bitcoin price reacts to security risks
Bitcoin traded just below $65,000 as investors assessed the implications of the BTCPay exploit.
Uk.Finance.Yahoo

Community

Browse all →

Tracked Entities in This Story