BTCPay Lightning Node Exploit Drains Funds from Merchant Nodes
A critical vulnerability has been discovered in BTCPay's Lightning node deployments, allowing attackers to drain funds from merchant nodes. The issue was reported by members of the Bitcoin Red Team, a group of developers using AI models to scan bitcoin codebases for bugs.
BTCPay credited Craig Raw, Rob Hamilton, Calle and Evan Kaloudis with responsibly disclosing the flaw and helping analyze it. The company stated that its standard on-chain wallets are not affected by the credential flaw, but funds held inside LND's own on-chain wallet can still be at risk.
The exposure applies specifically to deployments using LND, and BTCPay has not yet published technical details of the vulnerability. A full postmortem is due in the coming days, giving operators time to patch their nodes.