{
  "id": 349445,
  "title": "BTCPay restricts remote Lightning access after attackers steal funds",
  "url": "https://urgent.news/2026/08/09/btcpay-restricts-remote-lightning-access-after-attackers-steal-funds",
  "topic": "world",
  "section": "World",
  "published": "2026-08-09T05:46:07.000Z",
  "source": {
    "name": "Cointelegraph",
    "slug": "cointelegraph",
    "url": "https://cointelegraph.com/news/btcpay-restricts-remote-lightning-access-after-attackers-steal-funds"
  },
  "original_language": "en",
  "account": null,
  "summary": "BTCPay Server has temporarily restricted public remote connections to Lightning Network nodes after attackers exploited a critical vulnerability to steal funds from drained Lightning nodes. The exact amount stolen and the number of affected operators remain unknown. BTCPay advises operators to check for unauthorized payments, unexpected channel closures, unfamiliar peers, and discrepancies in their records compared to onchain or Lightning balances. Version 2.4.2 of BTCPay Server installs LND version 0.21.1 and automatically regenerates macaroon credentials on standard BTCPay installations. Operators exposing LND through their own reverse proxy, Tor service, forwarded port, or another route outside BTCPay must rotate their credentials separately. The breach is the latest security incident involving widely used Bitcoin products, following a flaw in Coldcard hardware wallets that led to over $100 million in confirmed losses.",
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}