Lightning Node Vulnerability Exposes Merchants to Potential Losses
A critical vulnerability in BTCPay Server has allowed attackers to drain funds from Lightning nodes running LND, prompting urgent calls to update to version 2.4.2 or take servers offline.
The flaw exposed the credentials protecting affected Lightning nodes, enabling attackers to seize control and drain their channels. However, standard on-chain wallets used by BTCPay were not impacted.
Victims include hardware-wallet maker Foundation and bitcoin publication Citadel21, which reported that its Lightning node was swept. The company's BTCPay on-chain hot wallet remained untouched.
The vulnerability had already been reported to BTCPay by members of the Bitcoin Red Team, a group of developers who have filed thousands of findings across hundreds of projects since beginning their efforts this week.