BTCPay Server Suffers Critical Vulnerability Attack, Urges Users to Update Immediately
BTCPay Server, a popular payment processor for Bitcoin, has confirmed that attackers exploited a critical vulnerability in their system. The attack allowed unauthenticated remote attackers to obtain LND .macaroon files, which carry permissions used to interact with an LND node.
The vulnerability was exploited by targeting files with the .macaroon extension. BTCPay Server has confirmed that users were affected and funds were stolen, but they are withholding full technical details until operators have time to patch their systems.
Users running LND on a BTCPay Server version earlier than 2.4.2 should update immediately to prevent further attacks. The project recommends checking for unexpected payments, channel closures, unfamiliar peers, and balance discrepancies after updating. Affected users may also need to review and rotate credentials associated with their node.
The incident highlights the importance of maintaining software security and credentials in the Bitcoin ecosystem. BTCPay Server has published additional precautions for different configurations following the incident, and users are advised to follow these instructions carefully.