BTCPay Server Flags Actively Exploited Critical Bug Tied to Funds Theft, Tells LND Users to Update
AI Market Summary
BTCPay Server disclosed a critical, actively exploited vulnerability affecting LND integrations in versions prior to 2.4.2, enabling attackers to obtain macaroon credentials, take over Lightning nodes, and steal funds. While the onchain wallet is unaffected, confirmed theft and a large estimated install base raise near-term operational and security risk for Bitcoin Lightning payment infrastructure, potentially pressuring risk appetite until upgrades are broadly deployed.
Impact level
● Medium
Affected assets
BTC/USDT-0.21%
AI Insight · BTC/USDTAI Insight
▼ Bearish
Trade now
⚠️ AI-generated insights are based on news content and are provided for informational purposes only. They do not constitute investment advice or represent the views of BingX. Investing involves risk. Please trade responsibly.
BTCPay Server on Aug. 9 released an urgent security notice warning that a critical vulnerability in all versions prior to 2.4.2—including the 2.4.2 release candidate—has been actively exploited, leading to theft of user funds.
According to the advisory, the flaw could allow an unauthenticated remote attacker to retrieve LND's .macaroon credential file, take control of the victim's LND (Lightning Network) node, and transfer funds. The team said it has confirmed real-world exploitation and is urging all LND users to upgrade immediately to BTCPay Server 2.4.2 and LND 0.21.1.
BTCPay Server noted its on-chain wallet is not affected. The amount stolen has not been disclosed.
BTCPay Server is a free, open-source, self-hosted Bitcoin payments processor positioned as a fee-free, intermediary-free solution for individuals and businesses. Core protocol contributors have estimated there may be hundreds of thousands of active BTCPay Server instances globally, and the project's main GitHub repository has been downloaded more than one million times.