Bitcoin Lightning Nodes Drained Overnight in BTCPay Server Attack
TLDR
- Attackers exploited a critical flaw in BTCPay Server, stealing funds from Lightning nodes running LND software
- The vulnerability exposed “.macaroon” credential files, giving attackers control over Lightning wallets
- BTCPay Server urged all users to update immediately to version 2.4.2 or take servers offline
- Hardware wallet maker Foundation and Bitcoin publication Citadel21 confirmed their nodes were drained
- The Bitcoin Red Team responsibly disclosed the flaw, but attackers were already exploiting it by the time the public warning went out
Attackers exploited a critical security flaw in BTCPay Server late Friday, draining Bitcoin funds from Lightning Network nodes and forcing an urgent call for users to update or shut down their servers.
There is a critical vulnerability being actively exploited on BTCPay Server, which can result in the loss of funds.
Please update your BTCPayServer to 2.4.2 by going to Admin Dashboard -> Server -> Maintenance -> Update & verify the 2.4.2 version string in the footer.
… Continue reading the full article at the original source below.
This content is automatically aggregated. Full credit goes to the original publisher (coincentral.com).


