Crypto
Home›Crypto›Market Structure›BTCPay urges Lightning node operators to update after…
BTCPay urges Lightning node operators to update after exploit drains nodes
The vulnerability enabled unauthenticated attackers to steal LND “.macaroon” credentials, letting them take control of affected Lightning nodes and drain their channels, while BTCPay’s standard on-chain wallets were not impacted.
CoinDesk reports BTCPay Server is warning Lightning node operators after attackers exploited a critical vulnerability to steal credentials from nodes running LND, leading to drained Lightning payment channels.
BTCPay said the flaw exposed “.macaroon” credential files without authentication, giving attackers the ability to seize control of affected Lightning nodes and move funds. It advised operators to update immediately to version 2.4.2 or take their servers offline.
BTCPay confirmed funds were stolen but has not disclosed how many users were affected or how much bitcoin was taken. The incident also did not impact BTCPay’s standard on-chain wallets, according to the project.
Victims identified by reports include hardware-wallet maker Foundation, whose CEO Zach Herbert said the company’s BTCPay Lightning node was drained overnight, with its channels closed, while its BTCPay on-chain hot wallet was untouched. Bitcoin publication Citadel21 also reported its Lightning node was swept, adding that little money was held there as BTCPay and the Bitcoin Red Team investigate and prepare a full postmortem.
Latest closeBitcoin $64,957.72 ▲0.1%