BTCPay Server Vulnerability Drains Bitcoin Lightning Nodes
A critical vulnerability in BTCPay Server versions before 2.4.2 allowed attackers to steal credential files and drain Bitcoin Lightning nodes.
This flaw let remote attackers take control of nodes and move funds without authentication.
At least two operators publicly reported their Lightning channels were emptied, though on-chain hot wallets were not affected.
Users are urged to update immediately and check for unauthorized transactions and channel closures, as stolen credentials remain valid until rotated.