BTCPay Server Patches Critical Vulnerability After Lightning Wallet Drain
BTCPay Server has released an urgent update to patch a critical vulnerability that allowed attackers to drain merchant Lightning wallets. The issue, which affected certain BTCPay Server setups using LND, involved the exposure of credential files, specifically .macaroon files.
.Macaroons can act like keys and grant access to node functions, making them extremely sensitive if exposed. The vulnerability was serious enough that attackers were able to drain merchant wallets through vulnerable setups.
BTCPay Server has released version 2.4.2 to fix the issue, which is considered a server-side security problem rather than a Bitcoin protocol exploit or native on-chain wallet failure. Merchants running affected setups are urged to update their systems as soon as possible and review LND exposure.
The recovery bounty, worth up to $190,000, offers 10% of returned funds to create an incentive for recovery or information. However, the more immediate step is making sure vulnerable systems are patched.