Uk.Finance.Yahoo Critical BTCPay Server Vulnerability Leads to Theft of Lightning Node Funds
Article Content
- •A critical vulnerability in BTCPay Server allowed unauthorized access to Lightning nodes.
- •Attackers exploited macaroon credential files, draining funds from affected nodes.
- •Operators must update to version 2.4.2 and regenerate credentials to secure their systems.
A critical vulnerability in BTCPay Server was exploited late on August 7, 2026, allowing attackers to drain funds from Lightning Network nodes by stealing macaroon credential files. The flaw, which affected versions prior to 2.4.2, enabled unauthorized access to nodes without needing to break Bitcoin's cryptography. Hardware wallet maker Foundation and Bitcoin publication Citadel21 confirmed their nodes were compromised. BTCPay issued an emergency patch (v2.4.2) and advised operators to update immediately or take their servers offline. The exact amount of Bitcoin stolen and the total number of affected users remain undisclosed. The vulnerability persisted even after software updates, requiring operators to manually regenerate credentials to fully secure their nodes. This incident highlights ongoing security risks within cryptocurrency infrastructure, particularly for self-hosted solutions.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (18)
Following this threat?
Track BTCPay in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical WSO2 API Manager Vulnerability Under Active Exploitation A critical vulnerability (CVE-2026-5430) in WSO2 API Manager is being actively exploited, allowing unauthenticated attackers to forge admin tokens via JWT authentication bypass. This flaw, which has a CVSS score of 10.0, affects multiple WSO2 products including API Manager, Universal Gateway, Traffic Manager, and API…
Critical Linux Kernel Vulnerability CVE-2025-39682 Under Active Exploitation A critical vulnerability (CVE-2025-39682) in the Linux kernel allows remote code execution through mishandling of zero-length TLS records. This flaw affects kTLS-enabled hosts running vulnerable kernel versions, exposing them to attackers without authentication. CISA added this vulnerability to its Known Exploited…