BTCPay Server Flaw Exploited to Empty Connected Lightning Nodes

AI مارکیٹ کا خلاصہ
A critical BTCPay Server vulnerability was actively exploited to drain funds from connected Lightning nodes by abusing persisted macaroon credentials, with confirmed losses among prominent operators. The incident highlights operational and security fragility in self-hosted Bitcoin merchant infrastructure and may temporarily reduce confidence in Lightning-based payment stacks. Urgent guidance to update or shut down servers could disrupt merchant uptime and elevate near-term infrastructure risk perceptions around Bitcoin.
اثر کی سطح
● درمیانہ
متاثرہ اثاثے
BTC/USDT+0.22%
AI تجزیاتی سمجھ · BTC/USDTAI تجزیاتی سمجھ
▼ Bearish
ابھی ٹریڈ کریں
⚠️ AI سے تیار کردہ تجزیاتی سمجھ خبروں کے مواد پر مبنی ہے اور صرف معلوماتی مقاصد کے لیے فراہم کی گئی ہے۔ یہ سرمایہ کاری کا مشورہ نہیں ہے اور نہ ہی BingX کے خیالات کی نمائندگی کرتی ہے۔ سرمایہ کاری میں رسک شامل ہے۔ براہ کرم ذمہ داری سے ٹریڈ کریں۔
BTCPay Server, the open-source payment processor used by thousands of Bitcoin merchants globally, issued an urgent security notice on Aug. 7 after attackers exploited a critical vulnerability to drain funds from connected Lightning nodes. The issue enabled unauthorized access to Lightning node credentials. At least two well-known Bitcoin community members said their nodes were wiped overnight. Foundation, maker of a popular hardware wallet lineup, and hodlonaut, who runs the Bitcoin publication Citadel21, reported their Lightning channels were force-closed and the funds swept. Their related hot wallets were not impacted, pointing to a failure tied specifically to how BTCPay Server handled Lightning node authentication. At the center of the incident were Lightning credentials known as "macaroons," which act like API keys and authorize actions on a Lightning node. According to the project, previously issued macaroons could remain valid even after operators installed earlier software updates. As a result, servers could stay exposed unless operators manually refreshed credentials. BTCPay Server shipped version 2.4.2 the same day as the alert and advised upgrading its NBXplorer backend to version 2.6.10. Operators were told to update immediately or shut down servers entirely to prevent additional losses. The project also emphasized the bug was distinct from an earlier authentication issue patched only days before. The incident has renewed attention on the risks of self-hosted infrastructure. Foundation's experience underscores how difficult it is to keep every layer of a self-hosted stack hardened, even for firms focused on user-controlled security. The exploit also lands amid broader scrutiny of Bitcoin infrastructure, following a recent Coldcard firmware flaw and AI-assisted reviews of key tools by the Bitcoin Red Team. BTCPay Server and the Bitcoin Red Team said technical write-ups on the exploit are expected in the coming days. The incident highlights a class of risk that can slip through routine patching: when remediation requires an extra manual step, the gap between being "updated" and being truly secure can become an easy target. Merchants running older BTCPay Server releases with Lightning enabled are being urged to treat the situation as urgent, with maintainers unusually direct in recommending shutdown if an immediate update isn't possible.