Bitcoin Lightning Nodes Drained as Attackers Exploit BTCPay Vulnerability
BTCPay Server, the free, open-source, self-hosted bitcoin payment processor, said attackers exploited a critical vulnerability present in every version before 2.4.2 and stole user funds. The project urged anyone running...
Archive context
Older archive item. Useful for background and entity history, but not a fresh market-moving signal.
BTCPay Server, the free, open-source, self-hosted bitcoin payment processor, said attackers exploited a critical vulnerability present in every version before 2.4.2 and stole user funds. The project urged anyone running its LND to update immediately.
The flaw let an unauthenticated remote attacker retrieve credential files, allowing them to take control of a node and move its funds.
Patching does not end the exposure, which is what makes this incident awkward for merchants. Credentials already stolen from a previously exposed server stay valid until they are rotated, so operators need to check their nodes for payments they did not make, unexpected channel closures and unfamiliar peers. BTCPay narrowed its guidance after the initial alert, confirming that its own on-chain wallets, including hot wallets, are not affected, though funds sitting in LND’s own on-chain wallet remain at risk because they belong to the compromised node.
At least two operators have gone public. Foundation, the maker of Passport hardware wallets, said its BTCPay Lightning node was drained overnight, with channels closed and funds swept, while its on-chain hot wallet was untouched, according to chief executive Zach Herbert. Citadel21, the bitcoin publication run by pseudonymous commentator hodlonaut, said its node was swept as well but held little.
BTCPay credited members of the Bitcoin Red Team, a group of developers that began aiming AI models at bitcoin codebases last week and has since filed thousands of findings across hundreds of projects, with disclosing the issue and helping analyze it. The incident lands days after a Coldcard firmware flaw tied to more than $100 million in confirmed losses.
Related Listen: Inside the Coldcard Hack That Drained Over $100 Million in Bitcoin: Uneasy Money
{"@context":"http:\/\/schema.org\/","@id":"https:\/\/unchainedcrypto.com\/bitcoin-lightning-nodes-drained-as-attackers-exploit-btcpay-vulnerability\/#arve-youtube-cd-_g0jvf_e","@type":"VideoObject","embedURL":"https:\/\/www.youtube-nocookie.com\/embed\/cD-_G0Jvf_E?feature=oembed&iv_load_policy=3&modestbranding=1&rel=0&autohide=1&playsinline=1&autoplay=0"}
The post Bitcoin Lightning Nodes Drained as Attackers Exploit BTCPay Vulnerability appeared first on Unchained.
Why this matters
Bitcoin is showing up inside the Security Incidents theme, so this story is worth tracking for follow-through rather than treating it as a one-off headline.
Original source
Read on UnchainedRelated market context
Bitget Confirms $387.5 Million Security Breach as Revised On-Chain Accounting Reveals Wider Losses
Bitget raises breach losses to $387.5 million after Zcash and TRON transfers found. Attackers spoofed backend transaction data to...
Bitget’s hack just got $36 million bigger, and now there’s a bounty on the stolen crypto
Bitget has raised the estimated value of assets taken in its Sept. 24 breach to $387.5 million as exchanges and security firms mob...
SEC’s Hester Peirce wants to end crypto’s KYC honeypots before stablecoin rules create more of them
US Securities and Exchange Commission (SEC) Commissioner Hester Peirce wants financial firms to stop stockpiling customer data aft...
US Charges Man After Crypto Scam Wallets Received More Than $53M
TL;DR U.S. prosecutors have charged a Vietnamese national with money laundering tied to alleged cryptocurrency “pig butchering” sc...
North Korean Hackers Linked to $388M Bitget Crypto Exchange Theft: CEO
Bitcoin Magazine North Korean Hackers Linked to $388M Bitget Crypto Exchange Theft: CEO Hackers from North Korea targeted crypto e...
DeFi hack attack: Three exploits snatch $11M in a single day
Crypto and DeFi projects continue to be hacked at a dizzying pace, and few days in recent weeks have been incident-free. That said...