Hackers Drain Lightning Payment Servers in Latest Bitcoin Infrastructure Breach
BTCPay has issued an urgent warning to LND users, telling them to upgrade their software or take their servers offline after hackers gained access to credentials that could be used to control Lightning wallets and transfer funds.
The latest incident adds to a series of security concerns affecting Bitcoin infrastructure and specifically targets merchants using the Lightning Network to accept fast, low-cost BTC payments.
Attackers drained funds from Lightning nodes connected to BTCPay Server on Friday by exploiting a critical vulnerability that exposed sensitive authentication credentials, according to the project.
BTCPay confirmed that some funds were stolen and urged operators running LND, the most widely used Lightning node implementation, to upgrade to version 2.4.2 immediately or disconnect their servers.
The team has not disclosed the number of affected users or the total value of bitcoin lost in the attacks.
The vulnerability allowed remote attackers to access “.macaroon” files without authentication. These files function as credentials that authorize interactions with LND nodes. Once obtained, they could be used to gain control of a node and move funds.
Foundation, a hardware wallet company, was among the reported victims. CEO Zach Herbert said attackers emptied the company’s BTCPay Lightning node overnight, shutting its channels and sweeping the funds. The company’s separate BTCPay on-chain hot wallet was not affected.
Citadel21, the Bitcoin publication operated by pseudonymous commentator hodlonaut, also said its Lightning node had been drained, although it reported that only a small amount of bitcoin was stored there.
The flaw had been reported to BTCPay before the attack by members of the Bitcoin Red Team, a group of developers that has been using AI models to identify vulnerabilities in Bitcoin-related software. The group has uncovered thousands of potential issues across hundreds of projects.
BTCPay credited Craig Raw, Rob Hamilton, Calle, and Evan Kaloudis with responsibly reporting the vulnerability and helping investigate the attacks.
The researchers said they chose to disclose their findings quickly because other parties could independently uncover the same weaknesses. By the time BTCPay released its public warning, however, attackers were already exploiting the flaw against active servers.
BTCPay later clarified that its standard on-chain wallets, including hot wallets created within the platform, are not affected by the vulnerability.
The issue is limited to deployments running LND. Still, funds stored in LND’s own on-chain wallet may be exposed because that wallet is associated with the compromised Lightning node.
BTCPay has not released the full technical details of the vulnerability, giving operators time to patch their systems. The project said it plans to publish a complete postmortem in the coming days.
Share this content:













