BTCPay Server Users Hit by Critical Vulnerability
Users of BTCPay Server, a self-hosted bitcoin payment processor, were targeted by attackers who exploited a critical vulnerability and drained their Lightning nodes. The flaw was not disclosed in the project's changelog, but rather discovered by Craig Raw, the developer of Sparrow Wallet, after he fell victim to it.
Foundation, the company behind the Passport hardware wallet, reported that its node was swept overnight, with attacker draining all channels and funds. hodlonaut, a pseudonymous bitcoin commentator, also had his Lightning node drained, but fortunately did not lose much in funds.
BTCPay's founder, Nicolas Dorier, warned users of the vulnerability and advised them to update to version 2.4.2 or shut down their servers. However, since BTCPay is self-hosted, there is no operator who can patch on behalf of its users, leaving each merchant, exchange, and wallet running the software to apply the fix themselves.
Dorier credited Raw for working out what was happening and thanked the Bitcoin Red Team for their disclosure. However, it seems that the team's AI-assisted audits did not catch this particular flaw, which was discovered through a more manual approach.