BlocktoBlockto
BTCPay Server Vulnerability Drains Bitcoin Lightning Payment Nodes
NEWS

Photo: Illustrative

BTCPay Server Vulnerability Drains Bitcoin Lightning Payment Nodes

Attackers have exploited a critical vulnerability in BTCPay Server, draining funds from Lightning nodes running LND software, prompting urgent warnings for merchants to update immediately or take servers offline.

Laurisa
By Laurisa

Junior Author · August 8, 2026

2 min
Key takeaways
Attackers have exploited a critical vulnerability in BTCPay Server, draining funds from Lightning nodes running LND software, prompting urgent warnings for merchants to update immediately or take servers offline.
Credential Theft Enabled the Attacks BTCPay confirmed late Friday that funds were stolen after attackers exploited a flaw allowing unauthenticated remote access to ".macaroon" files, credentials that grant control over LND Lightning nodes.
Once obtained, these files let attackers take over nodes and move funds directly.

Attackers have exploited a critical vulnerability in BTCPay Server, draining funds from Lightning nodes running LND software, prompting urgent warnings for merchants to update immediately or take servers offline.

Credential Theft Enabled the Attacks

BTCPay confirmed late Friday that funds were stolen after attackers exploited a flaw allowing unauthenticated remote access to “.macaroon” files, credentials that grant control over LND Lightning nodes. Once obtained, these files let attackers take over nodes and move funds directly. The project urged anyone running LND, the most widely used Lightning node software, to update to version 2.4.2 immediately or disconnect their servers.

Known Victims Emerge

Hardware wallet maker Foundation confirmed it was hit, with CEO Zach Herbert saying attackers drained the company’s BTCPay Lightning node overnight and closed its channels, though its separate on-chain hot wallet remained untouched. Bitcoin publication Citadel21 also reported its Lightning node was swept, though with minimal funds held there. BTCPay has not disclosed the total number of affected users or amount stolen.

Vulnerability Was Already Flagged

The flaw had been reported to BTCPay by members of the Bitcoin Red Team, a group that recently began systematically applying AI models to bitcoin codebases and has filed thousands of findings across various projects this week. By the time BTCPay issued its public warning, attackers were already exploiting the bug against live servers. BTCPay clarified that standard on-chain wallets remain unaffected, with exposure limited specifically to LND-based deployments. A full technical postmortem is expected in the coming days.

How markets are positioning

Live market reaction

🛢️WTI Crude
+3.4%
Gold
+1.8%
Bitcoin
-1.8%
$DXY
+0.6%

Disclaimer

This content is for informational purposes only and does not constitute financial, investment, or legal advice. Cryptocurrency trading involves risk and may result in financial loss.

Exclusive partner offer

Start trading
with BloFin today

Up to $500 sign-up bonus and zero-fee trading on your first 30 days.

Buy crypto now

You will be redirected to BloFin

Share article

About the author

Laurisa
Laurisa

Emerging voice in crypto journalism with a background in fintech and digital economics. Covers DeFi, NFTs, and the evolving regulatory landscape.