DigitalMoneyBox Signal Desk
DigitalMoneyBox Crypto market intelligence
Browse sections
Security Unchained

Bitcoin Lightning Nodes Drained as Attackers Exploit BTCPay Vulnerability

BTCPay Server, the free, open-source, self-hosted bitcoin payment processor, said attackers exploited a critical vulnerability present in every version before 2.4.2 and stole user funds. The project urged anyone running...

82 /100
Market signal

High signal

Published in the last two hours. The story has cross-source confirmation.

Bitcoin Lightning Nodes Drained as Attackers Exploit BTCPay Vulnerability

BTCPay Server, the free, open-source, self-hosted bitcoin payment processor, said attackers exploited a critical vulnerability present in every version before 2.4.2 and stole user funds. The project urged anyone running its LND to update immediately.

The flaw let an unauthenticated remote attacker retrieve credential files, allowing them to take control of a node and move its funds.

Patching does not end the exposure, which is what makes this incident awkward for merchants. Credentials already stolen from a previously exposed server stay valid until they are rotated, so operators need to check their nodes for payments they did not make, unexpected channel closures and unfamiliar peers. BTCPay narrowed its guidance after the initial alert, confirming that its own on-chain wallets, including hot wallets, are not affected, though funds sitting in LND’s own on-chain wallet remain at risk because they belong to the compromised node.

At least two operators have gone public. Foundation, the maker of Passport hardware wallets, said its BTCPay Lightning node was drained overnight, with channels closed and funds swept, while its on-chain hot wallet was untouched, according to chief executive Zach Herbert. Citadel21, the bitcoin publication run by pseudonymous commentator hodlonaut, said its node was swept as well but held little.

BTCPay credited members of the Bitcoin Red Team, a group of developers that began aiming AI models at bitcoin codebases last week and has since filed thousands of findings across hundreds of projects, with disclosing the issue and helping analyze it. The incident lands days after a Coldcard firmware flaw tied to more than $100 million in confirmed losses.

Related Listen: Inside the Coldcard Hack That Drained Over $100 Million in Bitcoin: Uneasy Money

{"@context":"http:\/\/schema.org\/","@id":"https:\/\/unchainedcrypto.com\/bitcoin-lightning-nodes-drained-as-attackers-exploit-btcpay-vulnerability\/#arve-youtube-cd-_g0jvf_e","@type":"VideoObject","embedURL":"https:\/\/www.youtube-nocookie.com\/embed\/cD-_G0Jvf_E?feature=oembed&iv_load_policy=3&modestbranding=1&rel=0&autohide=1&playsinline=1&autoplay=0"}

The post Bitcoin Lightning Nodes Drained as Attackers Exploit BTCPay Vulnerability appeared first on Unchained.

Why this matters

Bitcoin is showing up inside the Security Incidents theme, so this story is worth tracking for follow-through rather than treating it as a one-off headline.

Original source

Read on Unchained

Same story, other sources

Cross-source coverage

2 sources

Related market context