TechNewsReel
Live

BTCPay Server Patches Critical Flaw After Lightning Node Exploits

Operators must update immediately as a vulnerability allowing remote access to LND credentials led to drained funds.

TechNewsReel Newsroom · August 8, 2026

A critical security vulnerability in BTCPay Server has been actively exploited to drain funds from Bitcoin Lightning nodes. The flaw allowed unauthenticated remote attackers to obtain .macaroon credential files for LND, granting them unauthorized access to node funds.

In response, BTCPay released version 2.4.2 to patch the vulnerability and urged operators to update immediately or shut down their servers. To further mitigate risk, the project recommended that users update NBXplorer to version 2.6.10. Several high-profile users, including the zine Citadel21 and hardware wallet manufacturer Foundation, reported their nodes were swept before a public warning could be issued.

Targeted Attacks

The exploit specifically targeted the Lightning Network layer. Zach Herbert, CEO of Foundation, noted that the attack was isolated to the Lightning node, stating, "This was just our BTCPay server that we use for payment processing, the hot wallet was untouched – only the lightning node was drained." This pattern remained consistent across reported cases: hot on-chain wallets stayed secure while Lightning funds were stolen.

A Week of Ecosystem Failures

This incident occurs during a period of significant security instability within the Bitcoin ecosystem. The BTCPay exploit follows a Coldcard firmware bug that resulted in the loss of approximately $114 million and the indefinite halting of the Boltz swap bridge following a series of AI-assisted attacks. The Bitcoin Red Team, a volunteer group utilizing AI-assisted audits, assisted in the analysis and disclosure of the BTCPay flaw, although the group noted the vulnerability was not detected during their initial scans.

The Risk of Self-Hosting

Because BTCPay Server is a self-hosted solution, the incident underscores a fundamental security challenge: there is no central authority to push mandatory updates. The safety of funds rests entirely on the diligence of individual merchants and operators to monitor security advisories and apply patches manually.

Furthermore, the nature of the exploit creates a lingering threat. Because attackers were able to steal .macaroon credentials, they may maintain access to a node even after the software is patched. Security experts emphasize that simply updating the software is insufficient; operators must perform a full credential refresh to lock out attackers who have already compromised their systems.

What to Watch

Operators should verify their current versions of BTCPay Server and NBXplorer immediately. While the primary patch is available, the industry is now watching for potential clones of the exploit targeting other self-hosted Bitcoin payment processors. It remains to be seen if further vulnerabilities will be uncovered as the Bitcoin Red Team and other auditors continue their review of the software's credential handling.

Sources

Get a notification when a big story breaks. A few a day at most — no spam.