News/Bitcoin/BTCPay Lightning Nodes Drained, BTC at…
Bitcoin

BTCPay Lightning Nodes Drained, BTC at $64,968; Emergency Patch to v2.4.2

Attackers stole LND ".macaroon" credentials to sweep Lightning channels; BTCPay urges v2.4.2 update as Foundation, Citadel21 confirm losses.

BTCPay Lightning Nodes Drained, BTC at $64,968; Emergency Patch to v2.4.2

Attackers drained bitcoin Lightning nodes running behind BTCPay Server late Friday, exploiting an unauthenticated flaw that exposed credentials controlling LND, the most widely used Lightning node software. BTCPay confirmed funds were stolen and urged every operator running LND to update immediately to version 2.4.2 or take their servers offline. Bitcoin traded near $64,968.63 as the incident unfolded, with BTCPay’s core on-chain wallets left untouched.

Macaroon credentials were the entry point

The vulnerability let a remote attacker pull LND’s “.macaroon” files without authentication — the credential tokens that grant software permission to operate a Lightning node. With those files in hand, attackers could take full control of a node, close its channels, and sweep the balance. BTCPay said the exploit was isolated to LND-backed Lightning setups; its standard on-chain hot wallets were not affected.

BTCPay has not disclosed how many operators were hit or the total bitcoin lost. The team and the Bitcoin Red Team are investigating and preparing a full postmortem.

Foundation and Citadel21 among confirmed victims

Hardware-wallet maker Foundation said attackers drained its BTCPay Lightning node overnight, closing channels and sweeping the funds, while its separate on-chain hot wallet remained secure. Chief Executive Zach Herbert confirmed the breach. Bitcoin publication Citadel21 also reported its Lightning node was swept in the same wave of attacks.

Both cases followed the same pattern: exposed macaroon credentials, unauthorized node control, and channel funds moved out before operators could react.

Why this matters for node operators

Lightning is the layer merchants and payment processors rely on for instant, low-fee bitcoin settlement, so a credential-level exploit against LND strikes at infrastructure many businesses treat as production-critical. BTCPay’s guidance is blunt: patch to 2.4.2 now, or disconnect the server from the internet until it’s updated. Operators who delay risk having active channels swept the same way Foundation’s and Citadel21’s were.

The incident adds to a rough stretch for bitcoin’s software stack, with the BTCPay flaw surfacing days after other infrastructure scares hit the ecosystem. On-chain wallets and cold storage were not implicated here, but the episode underscores that hot, internet-facing Lightning nodes carry a distinct attack surface separate from custody of the underlying bitcoin.

Read more: BTCPay Server Bug Forces Patch to v2.4.2 as Trezor Phishing Ad Hits Same Day

Sources

Related articles