BTCPay Server confirmed attackers exploited a critical vulnerability to steal funds from users running any version prior to 2.4.2. The flaw allowed unauthenticated remote attackers to obtain .macaroon credential files for LND, a common Lightning Network implementation, granting full control of affected nodes. The self-hosted Bitcoin payment processor released version 2.4.2 to close the vulnerability and urged all operators to update immediately through the maintenance dashboard.
Attackers Exploited Vulnerability to Steal LND Node Credentials
The vulnerability specifically targeted deployments using LND. Stolen .macaroon credentials handed attackers full control of LND nodes, enabling direct fund transfers. "We have confirmed that attackers exploited this vulnerability. Users were affected and funds were stolen. We are not publishing technical details yet because operators still need time to update," the team stated.
The risk applies only to LND setups. Other Lightning Network implementations and non-Lightning users face no credential exposure, though BTCPay Server still recommended updates. The project's own on-chain and hot wallets remain unaffected.
BTCPay Server Instructs Operators to Update to Version 2.4.2
Operators using LND must update to version 2.4.2 and LND 0.21.1 through the maintenance dashboard by navigating to Admin Dashboard > Server > Maintenance > Update. The update regenerates macaroons automatically. Operators unable to patch immediately were instructed to take servers offline.
BTCPay Server advised LND users to review node activity for unfamiliar peers, unexpected channel closures, and unauthorized payments.
Galaxy Research Confirms $111 Million Stolen in Coldcard Incident
The BTCPay Server disclosure follows a separate major security incident. Galaxy Research confirmed 1,719 Bitcoin (BTC), worth roughly $111 million, has been stolen from Coldcard users. The firm expects total losses to exceed $130 million once outstanding cases are verified.
Neither incident affected the Bitcoin protocol itself. Both exposed weaknesses in tools built around the network.
FAQ
What vulnerability did attackers exploit in BTCPay Server?
Attackers exploited a critical flaw in BTCPay Server versions prior to 2.4.2 that allowed unauthenticated remote access to .macaroon credential files for LND, granting full control of affected Lightning Network nodes.
How do BTCPay Server operators update to version 2.4.2?
Operators must navigate to Admin Dashboard > Server > Maintenance > Update and verify the 2.4.2 version string in the footer. The update automatically regenerates macaroons for LND users.
How much Bitcoin was stolen in the Coldcard incident?
Galaxy Research confirmed 1,719 BTC, worth approximately $111 million, has been stolen from Coldcard users, with total losses expected to exceed $130 million once all cases are verified.