- BTCPay Server temporarily restricted public remote access to affected LND nodes.
- Version 2.4.2 installs LND 0.21.1 and regenerates macaroon credentials on standard setups.
- Foundation and Citadel21 reported drained Lightning nodes, but losses were not disclosed.
BTCPay Server temporarily limited public remote connections to some Lightning Network nodes after a critical vulnerability was exploited to obtain credentials and move funds. The BTCPay attack affected nodes running Lightning Network Daemon, or LND, and prompted the project to block external wallet connections through a BTCPay Server domain or Tor onion address on Docker deployments. BTCPay said Lightning payments can still continue during the restriction. It also released version 2.4.2, which installs LND 0.21.1 and regenerates macaroon credentials on standard installations. Public reports from Foundation and Citadel21 showed that some operators suffered losses, although the amount stolen and total number of affected users remain unknown.
BTCPay attack prompts remote access restrictions
BTCPay said the temporary change is meant to reduce risk after attackers exploited a vulnerability tied to LND access. Under the restriction, external wallets such as Zeus can no longer connect through a BTCPay Server domain or a Tor onion address on Docker deployments. The project said this step is temporary and that Lightning payments are still able to continue.
According to BTCPay, the remote-access option will return only when the project considers it safe. Its advisory said the flaw let an unauthenticated remote attacker obtain macaroon credential files, which are used to control an LND node. If those credentials are exposed, an attacker can take control of the node and move its funds.
BTCPay attack update and operator checks
BTCPay said version 2.4.2 installs LND version 0.21.1 and automatically regenerates macaroon credentials on standard installations. The project also urged operators to inspect their systems for warning signs after the BTCPay attack. Those checks include looking for unauthorized payments, unexpected channel closures, unfamiliar peers and mismatches in onchain or Lightning balances.
The project added that not every exposure route is closed by the update alone. Operators who expose LND through their own reverse proxy, Tor service, forwarded port or another path outside BTCPay need to rotate credentials separately. BTCPay said independently managed access routes remain the operator’s responsibility even after installing the latest release.
Reported losses linked to the BTCPay attack
At least two operators publicly disclosed losses after the BTCPay attack. Foundation CEO Zach Herbert said the company’s Lightning node was drained overnight. He said the company’s hot wallet was not affected, but its Lightning channels were closed and the funds were swept. The company did not provide a loss figure in that disclosure.
Bitcoin publication Citadel21 also reported that its Lightning node had been swept. Neither Foundation nor Citadel21 disclosed the amount lost. BTCPay and the affected operators have not said how many total users were impacted, leaving the full scale of the incident unclear for now.
Bitcoin products face another security incident
BTCPay described the event as the latest security problem affecting widely used Bitcoin products. The report compared it with a separate Coldcard hardware-wallet flaw that was linked to more than $100 million in confirmed losses. In both cases, the incidents involved software or products surrounding Bitcoin rather than the Bitcoin protocol itself.
That distinction shaped the project’s response to the BTCPay attack. The issue centered on software infrastructure, remote Lightning access and credential handling for LND deployments. BTCPay’s immediate actions focused on limiting remote connections, updating software and advising operators to review balances, peers and channel activity for signs that their node may have been compromised.
Conclusion
The BTCPay attack led the project to temporarily restrict public remote access for affected LND nodes after attackers used a vulnerability to obtain macaroon credentials and move funds. BTCPay said Lightning payments can continue while version 2.4.2 installs LND 0.21.1 and regenerates credentials on standard setups. The project also warned that operators using their own reverse proxy, Tor service or other separate access paths must rotate credentials themselves. Public reports from Foundation and Citadel21 confirmed drained Lightning nodes, but neither disclosed the value lost. For now, the total amount stolen and the number of affected operators remain unknown.
Disclaimer
The information provided in this article is for informational purposes only and should not be considered financial advice. The article does not offer sufficient information to make investment decisions, nor does it constitute an offer, recommendation, or solicitation to buy or sell any financial instrument. The content is opinion of the author and does not reflect any view or suggestion or any kind of advise from CryptoNewsBytes.com. The author declares he does not hold any of the above mentioned tokens or received any incentive from any company.
Featured image created by AI

