Bitcoin Payment Tool BTCPay Urges Update After Attackers Steal Funds

NewsSat, 08 Aug 2026 10:40:16 UTC2 hours ago
Bitcoin Payment Tool BTCPay Urges Update After Attackers Steal Funds

BTCPay Server confirmed that attackers exploited a critical flaw to steal funds from users running any version prior to 2.4.2 and urged operators to update immediately.

The self-hosted Bitcoin payment processor released version 2.4.2 to close the vulnerability. The issue allowed an unauthenticated remote attacker to obtain .macaroon credential files for LND, a common Lightning Network implementation.

What BTCPay Server Users Must Do

The stolen credentials could hand an attacker full control of an LND node. From there, the attacker could move funds directly out of the node.

"We have confirmed that attackers exploited this vulnerability. Users were affected and funds were stolen. We are not publishing technical details yet because operators still need time to update," the team said.

Follow us on X to get the latest news as it happens

Read from Source · beincrypto.com ↗
This content is automatically aggregated. Full credit goes to the original publisher (beincrypto.com).

Related