
BTCPay Server has released an emergency security update after confirming that attackers exploited a critical vulnerability to access Lightning Network nodes and steal funds.
There is a critical vulnerability being actively exploited on BTCPay Server, which can result in the loss of funds.
— BTCPay Server (@BtcpayServer) August 7, 2026
Please update your BTCPayServer to 2.4.2 by going to Admin Dashboard -> Server -> Maintenance -> Update & verify the 2.4.2 version string in the footer.
If you…
The flaw affects every BTCPay Server release before version 2.4.2, including release-candidate versions of the update.
It specifically threatens installations connected to LND, one of the most widely used implementations of the Lightning Network.
According to BTCPay Server’s security advisory, the vulnerability allowed a remote attacker without authentication to retrieve files carrying the .macaroon extension.
LND uses macaroons as credentials that determine what actions an application can perform on a node.
Access to sufficiently privileged credentials could therefore allow an attacker to control the node and transfer its funds.
BTCPay Server reported that the attacks it examined were directed at those credential files.
The project has confirmed both unauthorized exploitation and financial losses but has not disclosed the total amount stolen or the number of affected operators.
Hardware-wallet company Foundation was among the victims. CEO Zach Herbert reported that an attacker emptied the company’s BTCPay Lightning node and closed its payment channels.
How many BTCPay lightning nodes were swept? Our Foundation node was drained overnight by attackers. https://t.co/nt5OFBXB4j
— Zach Herbert 🇺🇸 (@zherbert) August 7, 2026
The company’s separate BTCPay on-chain hot wallet was not compromised.
Citadel21, a Bitcoin publication operated by the pseudonymous commentator hodlonaut, also reported that its Lightning node had been emptied.
This is an ongoing attack on BTCPayserver users.
— hodlonaut #BIP-110 (@hodlonaut) August 7, 2026
Citadel21's lightning node was just swept. Fortunately there were not much funds there, due to cautionary steps before BIP-110 activation.
Praying for all other affected users. https://t.co/YhdHhoPncH pic.twitter.com/4iRj1HJptL
The publication said the node contained only a small balance at the time.
BTCPay initially advised users to move funds from on-chain wallets as a precaution.
After investigating further, the project narrowed the affected systems to deployments using LND.
BTCPay Server reported that wallets created within its software, including on-chain hot wallets, were not affected by the vulnerability.
The project cautioned, however, that funds in LND’s on-chain wallet could remain at risk because the wallet is part of the affected LND node.
According to the project’s advisory, the credential exposure is limited to deployments using LND.
BTCPay stated that installations using other Lightning implementations, along with servers that do not use Lightning, are not subject to this specific risk.
BTCPay advised LND operators to install BTCPay Server 2.4.2 and verify that their nodes are running LND 0.21.1. It recommended taking affected servers offline when an immediate update is not possible.
The project noted that the update automatically generates new LND macaroons. It also advised operators to review node activity for unauthorized payments, unexpected channel closures, unfamiliar peers and unexplained balance changes.
Users who expose LND through independently configured reverse proxies, forwarded ports, Tor services or other routes were advised to rotate the credentials for those connections.
Version 2.4.2 also temporarily removes public access to the LND application programming interface on Docker deployments.
BTCPay explained that the change may prevent external wallets such as Zeus from connecting through a BTCPay Server domain or Tor address while the restriction remains in place.
BTCPay attributed the private disclosure of the vulnerability to security researchers and credited Craig Raw, Rob Hamilton, Calle, and Evan Kaloudis with its identification and analysis.
The project has not released technical details of the flaw, citing the need to give operators additional time to update affected systems. It plans to publish a more detailed postmortem in the coming days.
