Uk.Finance.Yahoo
Critical BTCPay Server Vulnerability Leads to Theft of Lightning Node Funds
Article Content
A critical vulnerability in BTCPay Server was exploited late on August 7, 2026, allowing attackers to drain funds from Lightning Network nodes by stealing macaroon credential files. The flaw, which affected versions prior to 2.4.2, enabled unauthorized access to nodes without needing to break Bitcoin's cryptography. Hardware wallet maker Foundation and Bitcoin publication Citadel21 confirmed their nodes were compromised. BTCPay issued an emergency patch (v2.4.2) and advised operators to update immediately or take their servers offline. The exact amount of Bitcoin stolen and the total number of affected users remain undisclosed. The vulnerability persisted even after software updates, requiring operators to manually regenerate credentials to fully secure their nodes. This incident highlights ongoing security risks within cryptocurrency infrastructure, particularly for self-hosted solutions.
Key Points: • A critical vulnerability in BTCPay Server allowed unauthorized access to Lightning nodes. • Attackers exploited macaroon credential files, draining funds from affected nodes. • Operators must update to version 2.4.2 and regenerate credentials to secure their systems.
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.