Critical BTCPay Server Vulnerability Leads to Theft of Lightning Node Funds

Critical BTCPay Server Vulnerability Leads to Theft of Lightning Node Funds

First seen 8 Aug 2026, 15:04 UTC CryptobriefingUk.Finance.YahooTechtimesCryptorankFinance.Biggo+11 72.8

Article Content

Browse articles
ThreatCluster

A critical vulnerability in BTCPay Server was exploited late on August 7, 2026, allowing attackers to drain funds from Lightning Network nodes by stealing macaroon credential files. The flaw, which affected versions prior to 2.4.2, enabled unauthorized access to nodes without needing to break Bitcoin's cryptography. Hardware wallet maker Foundation and Bitcoin publication Citadel21 confirmed their nodes were compromised. BTCPay issued an emergency patch (v2.4.2) and advised operators to update immediately or take their servers offline. The exact amount of Bitcoin stolen and the total number of affected users remain undisclosed. The vulnerability persisted even after software updates, requiring operators to manually regenerate credentials to fully secure their nodes. This incident highlights ongoing security risks within cryptocurrency infrastructure, particularly for self-hosted solutions.

Key Points: • A critical vulnerability in BTCPay Server allowed unauthorized access to Lightning nodes. • Attackers exploited macaroon credential files, draining funds from affected nodes. • Operators must update to version 2.4.2 and regenerate credentials to secure their systems.

Timeline

2026-08-07
Vulnerability exploited
Attackers exploited a flaw in BTCPay Server, draining funds from Lightning nodes. Hardware wallet Foundation and Citadel21 confirmed losses.
Techtimes
2026-08-07
Emergency patch released
BTCPay Server released version 2.4.2 to address the critical vulnerability and advised immediate updates.
Finance.Biggo
2026-08-08
Public confirmation of theft
BTCPay confirmed that funds were stolen from Lightning nodes, urging operators to update or shut down servers.
Uk.Finance.Yahoo
2026-08-08
Details of the vulnerability disclosed
The vulnerability allowed attackers to obtain macaroon files, granting full control over Lightning nodes.
Cryptobriefing