BTCPay Server Restricts Lightning Network Access After Hack Drains Nodes
TLDR
- BTCPay Server temporarily blocked external remote connections to Lightning Network nodes after attackers exploited a critical vulnerability
- Attackers obtained “macaroon” credential files used to control LND nodes, allowing them to move funds
- Version 2.4.2 patches the flaw and automatically rotates credentials on standard installations
- Foundation CEO Zach Herbert confirmed his company’s Lightning node was drained overnight
- Bitcoin publication Citadel21 also reported its Lightning node was swept, though neither disclosed amounts lost
BTCPay Server has temporarily blocked public remote connections to Lightning Network nodes after attackers used a critical security flaw to steal funds from at least two operators.
⚠️ALERT: An actively exploited BTCPay Server flaw is draining merchant Lightning nodes.
Attackers can remotely grab credential files from BTCPay deployments running LND and empty the node, with hardware wallet maker Foundation among the confirmed victims, per CoinDesk.
BTCPay… pic.twitter.com/558xdhTbjm
… Continue reading the full article at the original source below.
This content is automatically aggregated. Full credit goes to the original publisher (coincentral.com).

