BTCPay Server Lightning Node Hack Drains Funds from Thousands of Merchants
A critical vulnerability in BTCPay Server, an open-source payment processor used by thousands of Bitcoin merchants worldwide, has allowed attackers to drain funds from connected Lightning nodes. The flaw, which was exploited on August 7, gave unauthorized access to Lightning node credentials, even after users had applied previous software updates.
According to the project's security alert, the vulnerability centered on macaroons, API keys that grant permission to perform actions on a Lightning node. These credentials persisted even after software updates, and operators who had updated their BTCPay Server installations were still exposed because the old macaroons remained valid.
BTC Foundation, the company behind a popular line of hardware wallets, and hodlonaut, a prominent Bitcoin community member, both reported that their Lightning channels were force-closed and funds swept clean. Their associated hot wallets were not affected, which suggests that the attack was specific to how BTCPay Server handled Lightning node authentication.
The project has released version 2.4.2 of BTCPay Server, along with guidance to upgrade its NBXplorer backend to version 2.6.10. Operators are recommended to either update immediately or shut down their servers entirely to prevent further losses.