Key Points
- A severe security vulnerability in BTCPay Server enabled hackers to siphon Bitcoin from Lightning nodes powered by LND software
- Attackers gained unauthorized access to “.macaroon” authentication files, granting them full control over Lightning wallets
- BTCPay Server issued an emergency alert instructing all users to upgrade to version 2.4.2 or disconnect their servers immediately
- Victims include hardware wallet manufacturer Foundation and Bitcoin media outlet Citadel21, both reporting drained nodes
- Despite responsible disclosure by the Bitcoin Red Team, hackers had already begun exploiting the vulnerability when the public advisory was released
A serious security breach in BTCPay Server resulted in the theft of Bitcoin from Lightning Network nodes late Friday evening, prompting an emergency advisory for users to either apply critical updates or disconnect their systems immediately.
BTCPay Server is a popular open-source payment processing platform that enables merchants and organizations to receive Bitcoin payments in a self-custodial manner, eliminating dependence on third-party service providers.
The Nature of the Security Flaw
The security weakness enabled unauthorized remote attackers to obtain “.macaroon” files without authentication. These files function as authorization credentials that allow applications to communicate with and control an LND Lightning node.
LND represents the most commonly deployed software for operating Lightning nodes. With these stolen credential files in hand, attackers gained complete authority over targeted nodes and executed unauthorized fund transfers.
BTCPay acknowledged the theft of funds and issued an immediate directive for all users to upgrade to version 2.4.2. Users unable to implement the update were instructed to completely disable their servers until the security patch could be installed.
The development team has not revealed the number of compromised users or the aggregate amount of stolen Bitcoin.
Foundation, a hardware wallet manufacturer, verified that its BTCPay Lightning node suffered a complete fund drainage during the overnight attack. Company CEO Zach Herbert reported that the attackers forcibly closed the company’s payment channels and transferred all available funds. The company’s on-chain hot wallet remained secure.
Bitcoin media platform Citadel21, operated by pseudonymous Bitcoin advocate hodlonaut, similarly confirmed its Lightning node was emptied. The organization noted that minimal funds were stored on the node at the time of the breach.
BTCPay emphasized that conventional on-chain wallets within the BTCPay system are unaffected by this credential vulnerability. Nevertheless, Bitcoin stored in LND’s internal on-chain wallet remains vulnerable because it falls under the jurisdiction of the compromised node infrastructure.
Recommended Security Measures Following Update
Following installation of the security patch, BTCPay recommended users regenerate all macaroon credential files and the macaroon database, change authentication tokens associated with Lightning Network backends, and transfer Bitcoin from any hot wallets established within BTCPay before creating replacement wallets.
These protective measures are designed to invalidate any compromised credentials that may have been obtained by malicious actors.
Discovery and Disclosure Timeline
The Bitcoin Red Team, a developer collective that recently commenced automated security testing of Bitcoin software repositories using AI-powered analysis, confidentially submitted the vulnerability report to BTCPay. Security researchers Craig Raw, Rob Hamilton, Calle, and Evan Kaloudis received acknowledgment for their ethical disclosure practices.
The team explained their decision to publish findings rapidly was driven by the likelihood that independent attackers would identify identical vulnerabilities. Evidence indicates that exploitation had already commenced before BTCPay’s public security alert was disseminated.
BTCPay has withheld technical specifications of the vulnerability from public disclosure. A comprehensive incident analysis and postmortem report is anticipated within the next several days.



