BTCPay restricts remote Lightning access after attackers steal funds
Foundation and Citadel21 reported drained Lightning nodes, but the total amount stolen and number of affected operators remain unknown.
BTCPay Server has temporarily restricted public remote connections to Lightning Network nodes after attackers exploited a critical vulnerability to steal funds from drained Lightning nodes. The exact amount stolen and the number of affected operators remain unknown. BTCPay advises operators to check for unauthorized payments, unexpected channel closures, unfamiliar peers, and discrepancies in their records compared to onchain or Lightning balances.
Version 2.4.2 of BTCPay Server installs LND version 0.21.1 and automatically regenerates macaroon credentials on standard BTCPay installations. Operators exposing LND through their own reverse proxy, Tor service, forwarded port, or another route outside BTCPay must rotate their credentials separately. The breach is the latest security incident involving widely used Bitcoin products, following a flaw in Coldcard hardware wallets that led to over $100 million in confirmed losses.
Brief written by urgent.news from Cointelegraph's own syndicated text. Machine-written — it may contain errors, so check the original before relying on it.



