BTCPay Server has taken the precautionary step of temporarily blocking public remote connections to Lightning Network nodes after a serious security vulnerability was exploited, leading to the theft of funds from multiple operators.
The breach involved attackers exploiting a flaw to access “macaroon” credential files, which are essential for controlling Lightning Network Daemon (LND) nodes. Once these credentials were compromised, the attackers could freely transfer funds from the affected nodes.
In response to the incident, BTCPay Server has restricted external wallets, including popular connections like Zeus, from accessing Lightning Network nodes through BTCPay’s domain or Tor onion addresses on Docker deployments. The company has reassured users that while remote access is curtailed, Lightning payments remain operational, and access will be restored once a thorough security assessment confirms safety.
Patch Released
To combat the vulnerability, BTCPay Server rolled out version 2.4.2, which upgrades LND to version 0.21.1 and implements automatic regeneration of macaroon credentials for standard installations. However, operators who manage their LND through their own reverse proxies or Tor services must rotate their credentials independently, as the update does not alter access routes that are not controlled by BTCPay.
BTCPay has urged all operators to scrutinize their accounts for any unauthorized transactions, unexpected channel closures, unfamiliar peers, and discrepancies in balances, both onchain and within Lightning.
Confirmed Victims of the Attack
Zach Herbert, CEO of hardware wallet manufacturer Foundation, confirmed that his company’s Lightning node was drained overnight. He clarified, however, that their hot wallet remained unaffected, though the Lightning channels were closed, and the funds were swept away.
Additionally, the Bitcoin publication Citadel21 reported that its Lightning node had also been compromised. Neither organization has disclosed the total amount of funds lost in the incident, and the full scope of affected operators is still unclear.
This breach follows a separate incident linked to a Coldcard hardware wallet vulnerability that resulted in confirmed losses exceeding $100 million. While both situations raised alarms regarding Bitcoin’s surrounding infrastructure, BTCPay has stated that the two incidents are unrelated, emphasizing the need for heightened security awareness among operators.
BTCPay plans to restore remote access functionality once it is deemed safe, but no specific timeline has been provided. Operators are strongly advised to install the latest update immediately and monitor their node activity for any signs of unauthorized access.
