Crypto news

09.08.2026
14:31

BTCPay Server attacked: critical LND vulnerability led to theft of funds — urgent update required

The BTCPay Server team has confirmed the exploitation of a critical vulnerability that led to the direct theft of funds from some users. Attackers exploited a security flaw, gaining remote access to confidential data. Developers strongly urge all operators to immediately update their software, as any version below 2.4.2 is at risk.

The core issue and affected components

During the investigation, it was found that the vulnerability allowed an unauthorized party to remotely steal .macaroon authentication files used to manage LND nodes — one of the most common implementations of the Lightning Network. Obtaining these files gives an attacker full control over the node, opening direct access to funds in channels.

Version 2.4.2, released by developers, completely eliminates this flaw. It is important to emphasize that only nodes with integrated LND were affected by the attack. Users without Lightning functionality and other network configurations were not impacted. Nevertheless, I strongly advise everyone, without exception, to update their software — neglecting security patches in the current environment is unacceptable.

What operators should do

Operators using LND need to update to BTCPay Server version 2.4.2 and LND 0.21.1 as soon as possible via the admin panel. The macaroon files will be regenerated automatically during the update process. For those who cannot install the patch immediately, the only safe solution is to completely shut down the servers.

Additionally, I recommend that all LND operators carefully review their node history: pay attention to suspicious connections, unexpected channel closures, and unauthorized transactions. These signs may indicate that the node has already been compromised.

Context: the second serious attack in a week

This incident is the second major blow to bitcoin infrastructure security in recent days. Earlier, Galaxy Research analysts confirmed the theft of 1719 BTC (about $111 million) from Coldcard hardware wallet users. According to expert estimates, the final damage could exceed $130 million after reviewing all attack cases.

Neither attack affected the bitcoin protocol itself, which underscores its reliability. The vulnerabilities were found in tools built on top of it. This is yet another reminder: security in cryptocurrencies begins with hygiene in using specialized software.

My comment: We are witnessing a worrying trend: attackers are increasingly targeting not the base protocol, but peripheral services and tools that are considered trusted. The BTCPay Server incident is a signal for the entire community. Node operators must reconsider their security protocols and not delay updates, otherwise the cost of hesitation will be measured in direct financial losses.