Uk.Finance.Yahoo
Critical BTCPay Server Vulnerability Exploited, Draining Lightning Node Funds
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
On August 7, 2026, a critical vulnerability in BTCPay Server was exploited, allowing attackers to drain funds from Lightning nodes. The flaw involved unauthorized access to Lightning node credentials, specifically 'macaroons', which persisted after software updates. Prominent victims included hardware wallet maker Foundation and Bitcoin publication Citadel21, both confirming losses from their Lightning channels. BTCPay Server issued an urgent alert, urging operators to update to version 2.4.2 or shut down their servers. The attack highlights the challenges of maintaining security in self-hosted Bitcoin infrastructures. A detailed analysis of the exploit is expected in the coming days. The incident comes amid increased scrutiny of Bitcoin infrastructure security.
Key Points: • A critical vulnerability in BTCPay Server allowed unauthorized access to Lightning node credentials. • Prominent victims include hardware wallet maker Foundation and Bitcoin publication Citadel21. • BTCPay Server has urged operators to update immediately to prevent further losses.