BTCPay Blocks Remote Access to Lightning Nodes After Attackers Exploit Vulnerability
BTCPay Server has temporarily restricted public remote connections to Lightning Network nodes running the LND software after attackers exploited a critical vulnerability to steal funds.
The project warned that exposed credentials could enable attackers to take control of the node and move funds, prompting BTCPay to block external wallets from connecting through its domains or Tor onion addresses in Docker deployments.
BTCPay Server's update version 2.4.2 installs LND version 0.21.1 and automatically regenerates macaroon credentials on standard installations, forcing the authorization state to reset for typical deployments.
The project advised operators to inspect their nodes for signs of compromise, including unauthorized payments, unexpected channel closures, unfamiliar peers, and balance discrepancies as indicators of theft.