Another Bitcoin infrastructure exploit hits, this time draining Lightning payment servers

A critical vulnerability in BTCPay Server has allowed attackers to drain funds from Lightning Network nodes by stealing credential files. The project has urged users to update their software immediately to prevent further exploitation.
Why it matters
This exploit highlights the ongoing security risks in decentralized financial infrastructure and the importance of rapid vulnerability disclosure.
Attackers drained Lightning nodes running behind BTCPay Server late on Friday after exploiting a critical vulnerability that exposed the credentials protecting them, the team said in an X post .
BTCPay confirmed funds were stolen and told anyone running LND, the most widely used software for operating a Lightning node, to update immediately to version 2.4.2 or take the server offline.
The project has not disclosed how many users were hit or how much bitcoin was taken.
The flaw allowed an unauthenticated remote attacker to obtain “.macaroon” files, or credentials that give software permission to interact with an LND Lightning node. BTCPay said the attacks it reviewed targeted those files, which could then be used to take control of the node and move funds.
Get smarter about the news
Sign up free for a feed built around what you actually care about, Dive Deeper research on any story, and the full text of every article.
Create free accountAlready have an account? Sign in