BTCPay Restricts Remote Access After Attackers Drain Lightning Nodes
BTCPay Server has restricted public remote connections to Lightning Network nodes running LND software after attackers exploited a critical vulnerability to obtain credentials and move funds.
The breach allowed an unauthenticated remote attacker to gain access to 'macaroon' credential files used to control LND, which could be used to take control of an LND node and move its funds.
BTCPay has temporarily restricted external wallets from connecting through a BTCPay Server domain or Tor onion address on Docker deployments to prevent further unauthorized activity.
The project advises operators to check for unexpected channel closures, unfamiliar peers, and discrepancies in their onchain or Lightning balances.
At least two operators have publicly reported losses after their Lightning nodes were swept. Foundation CEO Zach Herbert clarified that his company's hot wallet was unaffected, while its Lightning channels were closed and the funds were swept.