BTCPay has warned users running LND to either update immediately or shut down their servers after attackers stole credentials that can control Lightning wallets and move funds.
A challenging week for Bitcoin’s software has worsened, this time affecting merchants that accept BTC payments via the Lightning Network — a layer built for fast, low-cost transactions.
On Friday, attackers exploited a critical vulnerability in BTCPay Server setups, exposing credentials tied to Lightning nodes and allowing funds to be drained, the team said in a post on X.
BTCPay confirmed the theft and urged all LND users — the most widely used Lightning node software — to upgrade to version 2.4.2 or take their servers offline as a precaution.
The project has not disclosed how many users were impacted or the total amount of bitcoin lost.
The flaw allowed unauthenticated remote attackers to access “.macaroon” files, which act as permission keys for interacting with an LND node. By obtaining these files, attackers could take control of nodes and transfer funds.
Hardware wallet maker Foundation was among those affected. CEO Zach Herbert said attackers emptied the company’s BTCPay Lightning node overnight, closing channels and withdrawing funds, while its on-chain hot wallet remained unaffected.
Bitcoin publication Citadel21, run by pseudonymous commentator hodlonaut, also reported that its Lightning node had been drained, though it said only a small amount of funds was involved.
The vulnerability had already been flagged to BTCPay by members of the Bitcoin Red Team — a group of developers using AI tools to scan bitcoin codebases — which has reported thousands of issues across hundreds of projects.
BTCPay credited contributors Craig Raw, Rob Hamilton, Calle, and Evan Kaloudis for responsibly disclosing the flaw and helping analyze it.
The group said it moved quickly to publish findings because others could uncover the same bugs. By the time BTCPay issued its warning, attackers were already exploiting the vulnerability on live servers.
After its initial alert, BTCPay clarified that its standard on-chain wallets, including those generated within the platform, are not affected.
The issue specifically impacts deployments using LND. However, funds held in LND’s own on-chain wallet may still be exposed, as they are linked to the compromised Lightning node.
BTCPay has not yet released full technical details, noting that operators need time to secure their systems. A detailed postmortem is expected in the coming days.

































