BTCPay Server Flaw Exploited to Empty Connected Lightning Nodes
AI Market Summary
A critical BTCPay Server vulnerability was actively exploited to drain funds from connected Lightning nodes by abusing persisted macaroon credentials, with confirmed losses among prominent operators. The incident highlights operational and security fragility in self-hosted Bitcoin merchant infrastructure and may temporarily reduce confidence in Lightning-based payment stacks. Urgent guidance to update or shut down servers could disrupt merchant uptime and elevate near-term infrastructure risk perceptions around Bitcoin.
Impact level
● Medium
Affected assets
BTC/USDT+0.11%
AI Insight · BTC/USDTAI Insight
▼ Bearish
Trade now
⚠️ AI-generated insights are based on news content and are provided for informational purposes only. They do not constitute investment advice or represent the views of BingX. Investing involves risk. Please trade responsibly.
BTCPay Server, the open-source payment processor used by thousands of Bitcoin merchants globally, issued an urgent security notice on Aug. 7 after attackers exploited a critical vulnerability to drain funds from connected Lightning nodes.
The issue enabled unauthorized access to Lightning node credentials. At least two well-known Bitcoin community members said their nodes were wiped overnight. Foundation, maker of a popular hardware wallet lineup, and hodlonaut, who runs the Bitcoin publication Citadel21, reported their Lightning channels were force-closed and the funds swept. Their related hot wallets were not impacted, pointing to a failure tied specifically to how BTCPay Server handled Lightning node authentication.
At the center of the incident were Lightning credentials known as "macaroons," which act like API keys and authorize actions on a Lightning node. According to the project, previously issued macaroons could remain valid even after operators installed earlier software updates. As a result, servers could stay exposed unless operators manually refreshed credentials.
BTCPay Server shipped version 2.4.2 the same day as the alert and advised upgrading its NBXplorer backend to version 2.6.10. Operators were told to update immediately or shut down servers entirely to prevent additional losses. The project also emphasized the bug was distinct from an earlier authentication issue patched only days before.
The incident has renewed attention on the risks of self-hosted infrastructure. Foundation's experience underscores how difficult it is to keep every layer of a self-hosted stack hardened, even for firms focused on user-controlled security. The exploit also lands amid broader scrutiny of Bitcoin infrastructure, following a recent Coldcard firmware flaw and AI-assisted reviews of key tools by the Bitcoin Red Team.
BTCPay Server and the Bitcoin Red Team said technical write-ups on the exploit are expected in the coming days. The incident highlights a class of risk that can slip through routine patching: when remediation requires an extra manual step, the gap between being "updated" and being truly secure can become an easy target. Merchants running older BTCPay Server releases with Lightning enabled are being urged to treat the situation as urgent, with maintainers unusually direct in recommending shutdown if an immediate update isn't possible.