Critical BTCPay Server Vulnerability Drains Merchant Lightning Nodes Amid Bitcoin's Exploit Week
Key Takeaways
- •The flaw allowed unauthenticated remote access to LND macaroon credential files used by Lightning nodes.
- •BTCPay confirmed that attackers stole funds and told operators to upgrade to version 2.4.2 or take servers offline.
- •Foundation said its BTCPay Lightning node was drained, while its on-chain hot wallet was not affected.
- •Citadel21 also reported that its Lightning node was swept, though it said little money was stored there.
- •BTCPay said standard on-chain wallets generated inside the application were not affected, and a full postmortem is expected in the coming days.

Critical BTCPay Server Vulnerability Drains Merchant Lightning Nodes Amid Bitcoin's Exploit Week
A critical vulnerability in BTCPay Server enabled attackers to steal funds from Lightning nodes running LND, prompting urgent instructions for operators to update to version 2.4.2 or take their servers offline immediately.
The flaw allowed unauthenticated remote access to LND ".macaroon" credential files — the tokens that grant software permission to interact with an LND Lightning node. Armed with those credentials, attackers could seize control of affected nodes, close their channels, and sweep the funds. BTCPay confirmed that funds were stolen late on Friday and disclosed the attack in an X post.
BTCPay Server is a widely used open-source, self-hosted payment processor that lets merchants accept bitcoin without relying on third-party payment providers. For merchants who depend on it for day-to-day commerce, the vulnerability meant that the very tool designed to eliminate counterparty risk — self-custody of funds — became the attack vector itself.
BTCPay's standard on-chain wallets, including hot wallets generated inside the application, were not affected by the credential flaw. The exposure applies specifically to deployments using LND, the most widely used software implementation for operating a Lightning node. However, funds held inside LND's own on-chain wallet remain at risk because they sit under the compromised Lightning node's control.
The project has not disclosed how many users were affected or how much bitcoin was taken.
Known Victims
Hardware-wallet manufacturer Foundation was among the victims. Chief Executive Zach Herbert stated that attackers drained the company's BTCPay Lightning node overnight, closing its channels and sweeping the funds. Foundation's BTCPay on-chain hot wallet was untouched.
Citadel21, a bitcoin publication run by pseudonymous commentator hodlonaut, reported that its Lightning node had also been swept, though it noted that little money was held there.
Bitcoin Red Team Involvement
The vulnerability had already been reported to BTCPay by members of the Bitcoin Red Team — a group of developers that began directing AI models at bitcoin codebases earlier in the week and has since filed thousands of findings across hundreds of projects. BTCPay credited Red Team members Craig Raw, Rob Hamilton, Calle, and Evan Kaloudis with responsibly disclosing the issue and assisting in its analysis.
The group's stated rationale for publishing findings quickly was that independent researchers would inevitably arrive at the same bugs. By the time BTCPay issued its public warning, attackers were already exploiting the vulnerability against live servers.
Related: Bitcoin developers flag 85 critical bugs in an "extremely bad" situation
Scope and Next Steps
BTCPay narrowed the scope of its initial alert, clarifying that standard on-chain wallets generated inside BTCPay are not affected by the credential flaw. The exposure is limited to deployments using LND, though funds held in LND's own on-chain wallet can still be at risk because they fall under the compromised Lightning node.
BTCPay has not yet published technical details of the vulnerability, stating that operators need time to patch their systems. A full postmortem is expected in the coming days. BTCPay and the Bitcoin Red Team are continuing to investigate the incident.
The exploit adds to a difficult week for Bitcoin software security, this time directly affecting merchants who accept bitcoin (BTC) payments through Lightning, a separate layer built on top of Bitcoin for instant, low-cost transfers. With Lightning capacity growing as a payment rail, vulnerabilities in the infrastructure that merchants plug into carry broader implications for confidence in bitcoin as a medium of exchange.