TLDR
A critical BTCPay Server bug let attackers drain funds from some merchant Lightning nodes that accept Bitcoin payments via LND.
- Attackers abused a BTCPay Server vulnerability to steal LND credential files, gaining control of affected Lightning wallets and emptying channels.
- The incident hit self?hosted merchant payment servers (including Foundation and Citadel21), but did not compromise the Bitcoin blockchain or BTCPays standard on?chain wallets.
- BTCPay has shipped an emergency patch and investigation is ongoing; Lightning users should watch for full postmortems and broader security hardening around Bitcoin infrastructure.
Confidence: high because BTCPay maintainers and multiple independent reports describe the same exploit, impact, and patch.
Deep Dive
1. How Merchant Lightning Nodes Were Drained
Reports show attackers exploited a critical vulnerability in BTCPay Server, software used by merchants to accept Bitcoin via the Lightning Network. The flaw allowed unauthenticated remote access to LND .macaroon files, which are credentials that let software control a Lightning node. Once those credentials were stolen, attackers could close channels and move funds out of affected merchant nodes, effectively draining their Lightning balances. BTCPay urged operators to update immediately to version 2.4.2 or shut down servers, and confirmed funds were stolen in the Lightning payment servers exploit.
2. Scope, Impact, And What Was Not Hit
The exploited bug applies to BTCPay installations that use LND for Lightning; other Lightning setups and non?Lightning BTCPay users are not directly affected according to BTCPays own vulnerability notice. Hardware?wallet maker Foundation and Bitcoin publication Citadel21 reported that their Lightning nodes were swept, with one report citing about 3.1 BTC drained across two nodes. BTCPay has stated that its standard on?chain hot wallets were not impacted, and there is no evidence that the Bitcoin protocol itself was compromised. This exploit follows a separate Coldcard hardware wallet firmware bug that enabled brute?forcing of weak seeds and led to about $130 million in losses, as detailed in the Coldcard hardware wallet hack analysis.
The failures are in surrounding tools and infrastructure, not Bitcoins base layer, but they still create real loss risk for merchants and self?custody users who misconfigure or under?update their stack.
3. Response, Ongoing Audits, And What To Watch
BTCPay released version 2.4.2 that regenerates macaroons and closes the vulnerability, and has withheld full technical details while operators patch, with a more complete postmortem expected later in coordination with the volunteer Bitcoin Red Team. That group is running intensive AI?assisted audits across Bitcoin?related software and recently reported dozens of critical issues discovered in wallet and infrastructure code, as covered in a Bitcoin security campaign overview. For Lightning users and merchants, the near?term focus is on confirming updates, checking nodes for unfamiliar peers or unexpected channel closures, and watching for any follow?up disclosure that might expand (or narrow) the list of affected setups.
Conclusion
This exploit shows how a single configuration bug in a widely used payment server can translate into drained Lightning balances, even while Bitcoins base protocol remains intact. For crypto users, the practical takeaway is that self?custody and merchant infrastructure need the same patch discipline and security review as exchanges and DeFi, especially when relying on complex stacks like Lightning plus BTCPay. Watching the upcoming BTCPay postmortem and the broader Bitcoin security audit efforts will be important for understanding whether todays fixes are enough or whether deeper changes to Lightning?adjacent tooling are coming.
