BTCPay Flaw Drains Lightning Nodes Amid 'Rough Week' for Bitcoin Software
A critical vulnerability in BTCPay Server allowed attackers to drain funds from Lightning nodes running LND, prompting urgent calls to update to version 2.4.2 or take servers offline.
The flaw exposed unauthenticated access to LND '.macaroon' credential files, enabling attackers to seize control of affected nodes and drain their channels.
Victims included hardware-wallet maker Foundation and bitcoin publication Citadel21, which reported that their Lightning nodes were swept.
BTCPay credited the Bitcoin Red Team with responsibly disclosing the issue and helping analyze it, saying operators need time to patch before publishing technical details of the vulnerability.