In a troubling incident late Friday, a critical security flaw in BTCPay Server has led to significant losses for users operating Bitcoin Lightning Network nodes. The vulnerability allowed attackers to drain funds from these nodes, prompting an immediate call for all users to either update their software or take their servers offline.
BTCPay Server, a widely-used open-source Bitcoin payment processor, is designed to facilitate transactions for merchants and businesses without the need for third-party custodians. However, a recent exploitation of a vulnerability has put many users at risk.
What Was Exploited
The flaw permitted unauthenticated remote attackers to gain access to “.macaroon” files—credential files essential for software to interact with an LND (Lightning Network Daemon) node. With control over these files, attackers could manipulate the node to transfer funds out without authorization.
In response to the breach, BTCPay confirmed that funds had indeed been stolen and urged all users to upgrade to version 2.4.2 of the software. Users unable to perform the update were advised to shut down their servers entirely until they could implement the necessary patch.
While BTCPay has not disclosed the exact number of users affected or the total amount of Bitcoin stolen, reports indicate that hardware wallet company Foundation and Bitcoin publication Citadel21 were among those whose nodes were compromised. Foundation’s CEO, Zach Herbert, stated that attackers closed the company’s channels and emptied the funds, although its on-chain hot wallet remained intact. Citadel21 reported similar losses, albeit with minimal funds held at the time.
It’s important to note that standard on-chain wallets within BTCPay are not affected by this credential flaw. However, funds kept in LND’s own on-chain wallet remain vulnerable as they are managed under the compromised node.
Security Steps Advised After Patching
Following the update, BTCPay has recommended users refresh all macaroon files and the macaroon database, change authentication strings associated with Lightning Network backends, and move any Bitcoin from hot wallets created within BTCPay before generating new wallets. These precautionary measures are designed to eliminate any credentials that may have been obtained by attackers.
Who Found the Flaw
The vulnerability was responsibly disclosed by the Bitcoin Red Team, a group of developers who recently began running AI models against Bitcoin codebases. The team, consisting of researchers Craig Raw, Rob Hamilton, Calle, and Evan Kaloudis, reported the flaw privately to BTCPay. They emphasized the urgency of their findings, noting that outside attackers would likely exploit the same vulnerabilities independently. Unfortunately, by the time BTCPay issued its public warning, the exploitation had already begun.
As of now, BTCPay has not released detailed technical information regarding the vulnerability, but a comprehensive postmortem is expected in the coming days. The incident serves as a stark reminder of the vulnerabilities that can exist within the cryptocurrency ecosystem and the importance of maintaining updated software to safeguard against potential threats.
