BTCPay Server Flaw Exposes Bitcoin Lightning Wallets to Hackers
A critical flaw in BTCPay Server has been discovered, allowing hackers to drain Bitcoin Lightning wallets. The vulnerability, which affects users running LND software on their servers, allows attackers to steal credentials and seize control of funds held in Lightning channels.
The issue has already affected several prominent organizations, including hardware-wallet maker Foundation and bitcoin publication Citadel21. To prevent further losses, BTCPay Server users are urged to update to version 2.4.2 or take their servers offline immediately.
The flaw does not affect standard on-chain wallets but poses significant risks to funds held in Lightning channels. BTCPay and the Bitcoin Red Team are investigating the issue and will release a full report soon.