BTCPay Server Exploit Leads to Stolen Funds From LND Users
| |

BTCPay Server Exploit Leads to Stolen Funds From LND Users

Bitcoin Payment Processor BTCPay Server Exploited – Users Urged to Update After Funds Stolen

Key Takeaways

  • BTCPay Server confirmed a critical vulnerability that allowed attackers to steal funds from certain users.
  • The flaw affected versions prior to 2.4.2 and targeted deployments using LND for Lightning payments.
  • Attackers were able to obtain LND .macaroon credential files, potentially gaining full control of nodes.
  • Users are instructed to update to BTCPay Server 2.4.2 and LND 0.21.1 or take servers offline.
  • The incident follows a separate Coldcard-related exploit in which 1,719 BTC have been confirmed stolen.

Critical Vulnerability in BTCPay Server Allowed Credential Theft

BTCPay Server has confirmed that attackers exploited a critical flaw in its software, resulting in stolen funds. The issue affected any version prior to 2.4.2. According to the project team, the vulnerability enabled an unauthenticated remote attacker to obtain .macaroon credential files associated with LND, a widely used Lightning Network implementation.

Macaroons function as authentication credentials within LND. If obtained by an unauthorized party, they can provide extensive control over a Lightning node. In this case, BTCPay Server stated that the stolen credentials could allow attackers to move funds directly out of affected nodes.

The team acknowledged that users were impacted and that funds were stolen. Technical details of the exploit have not been published yet. BTCPay Server said this decision is intended to give operators time to update their systems before more information becomes public.

Impact Limited to LND Deployments

The risk applies specifically to BTCPay Server deployments that use LND. Other Lightning Network setups were not exposed to credential theft through this vulnerability. Users who rely solely on on-chain Bitcoin payments without Lightning integration were also not affected in terms of credential exposure.

BTCPay Server clarified that its own on-chain and hot wallets remain unaffected by the incident. The vulnerability concerned self-hosted instances operated by users running outdated versions of the software.

For operators using LND, the potential consequences are significant. With valid macaroons, an attacker could gain full control of the LND node and initiate unauthorized transactions. That includes closing channels or moving Lightning funds without the operator’s consent.

Mandatory Update to Version 2.4.2 and LND 0.21.1

To address the issue, BTCPay Server released version 2.4.2. Operators are instructed to update through the Admin Dashboard under Server, Maintenance, and Update. Users are advised to verify that the footer reflects the 2.4.2 version string after installation.

In addition, LND users are instructed to update to LND 0.21.1. The update process regenerates macaroons automatically, which invalidates previously compromised credentials.

For operators who cannot apply the update immediately, the project recommends taking servers offline as a precautionary measure.

BTCPay Server also advised LND users to review node activity. Specifically, operators should check for unfamiliar peers, unexpected channel closures, and payments they did not authorize. These indicators may signal unauthorized access.

The project communicated the urgency publicly, stating that the vulnerability was being actively exploited. This confirmation indicates that the issue was not theoretical but had already resulted in real losses.

Second Security Incident Involving Bitcoin Tools

The disclosure comes shortly after another major security incident affecting Bitcoin users. According to Galaxy Research, 1,719 Bitcoin have been confirmed stolen from Coldcard users. Based on victim reports, Galaxy Research stated that the value of the confirmed losses is approximately 111 million US dollars.

Galaxy Research added that additional coins are still being vetted and that total losses are expected to exceed 130 million US dollars once all cases are verified.

Neither the BTCPay Server exploit nor the Coldcard-related incident involved a breach of the Bitcoin protocol itself. In both cases, the weaknesses were identified in tools and infrastructure built around Bitcoin rather than in the underlying network.

Relevance for Operators Accepting Bitcoin and Lightning Payments

For businesses and platforms that accept Bitcoin payments, including those in sectors such as online services and digital commerce, BTCPay Server is widely used as a self-hosted payment processor. Deployments that integrate Lightning via LND rely on secure credential management to protect funds held in channels and nodes.

The confirmed exploitation underscores the operational risks associated with self-hosted infrastructure. When critical updates are released, delays in patching can expose nodes to active threats. In this case, attackers were able to leverage unauthenticated remote access to retrieve sensitive credential files.

For users evaluating crypto payment setups, the incident highlights the importance of version control, monitoring node activity, and promptly applying security patches when vulnerabilities are disclosed.

Our Assessment

BTCPay Server confirmed that a critical vulnerability in versions prior to 2.4.2 was actively exploited, leading to stolen funds from users running LND. The issue allowed attackers to obtain macaroon credentials and potentially take full control of affected nodes. An update to version 2.4.2 and LND 0.21.1 has been released, with instructions to regenerate credentials and review node activity. The disclosure follows a separate confirmed theft of 1,719 BTC from Coldcard users, with additional losses under review. In both cases, the incidents affected tools built around Bitcoin rather than the Bitcoin protocol itself.

Similar Posts

Leave a Reply

Your email address will not be published. Required fields are marked *