BTCPay Server Hackers Drain Funds from Lightning Network Nodes
A severe security vulnerability in BTCPay Server allowed hackers to gain unauthorized access to Lightning Network nodes, resulting in fund thefts from several prominent users.
The vulnerability, discovered by the Bitcoin Red Team, enabled remote attackers to access '.macaroon' files without authentication, which grant applications full administrative access to LND Lightning nodes. This allowed malicious actors to initiate unauthorized fund transfers.
BTCPay Server issued an emergency advisory requiring all users to upgrade to version 2.4.2 or temporarily shut down their systems to prevent further attacks. Foundation, a hardware wallet manufacturer, and Bitcoin media outlet Citadel21 were among the victims of the attack.