Key Takeaways
- BTCPay Server has suspended external remote access to Lightning Network nodes following the discovery of a severe security vulnerability that allowed attackers to steal funds
- Hackers gained access to “macaroon” authentication files that control LND nodes, enabling them to withdraw funds without authorization
- A security patch in version 2.4.2 addresses the vulnerability and automatically refreshes credentials for standard setups
- Foundation’s CEO Zach Herbert disclosed that his organization’s Lightning node was completely drained during the attack
- Citadel21, a Bitcoin-focused publication, similarly reported having its Lightning node compromised and emptied, with both entities withholding specific loss figures
BTCPay Server has implemented an emergency suspension of public remote access to Lightning Network nodes following a security breach that enabled attackers to exploit a serious vulnerability and drain funds from multiple operators.
ā ļøALERT: An actively exploited BTCPay Server flaw is draining merchant Lightning nodes.
Attackers can remotely grab credential files from BTCPay deployments running LND and empty the node, with hardware wallet maker Foundation among the confirmed victims, per CoinDesk.
BTCPay⦠pic.twitter.com/558xdhTbjm
ā Coin Bureau (@coinbureau) August 8, 2026
The security breach specifically targeted nodes operating Lightning Network Daemon software. Hackers successfully exploited the weakness to acquire “macaroon” authentication files, which serve as control mechanisms for LND nodes. With these credentials in hand, attackers gained unrestricted ability to transfer funds.
The implemented restriction blocks external wallet applications such as Zeus from establishing connections via BTCPay Server domains or Tor onion addresses on Docker-based deployments. BTCPay has clarified that Lightning payment functionality remains operational and that remote connectivity will be reinstated once security protocols have been verified as secure.
Security Patch Details
BTCPay published version 2.4.2 as an emergency security update. This release implements LND version 0.21.1 and includes automatic regeneration of macaroon authentication credentials for default configurations.
Users who have configured LND routing through custom reverse proxy setups, Tor services, or manually forwarded ports outside BTCPay’s standard configuration must manually regenerate their credentials. The security update does not automatically secure access pathways that operators have configured independently.
BTCPay has recommended that all node operators conduct thorough audits for suspicious transactions, unexpected channel terminations, unrecognized network peers, and any discrepancies in balances across both onchain and Lightning Network accounts.
Confirmed Victims of the Attack
Zach Herbert, CEO of Foundation, publicly acknowledged that his company’s Lightning node suffered a complete drainage during the nighttime hours. He subsequently provided clarification that the company’s hot wallet remained secure and uncompromised. The Lightning channels were forcibly closed and all funds were extracted by attackers.
Bitcoin media outlet Citadel21 has also confirmed that its Lightning node was completely emptied in the attack. Both affected parties have chosen not to reveal the exact monetary value of their losses.
The complete scope of the breach, including the total number of compromised operators, has not yet been determined.
This security incident occurs in the wake of a separate vulnerability discovered in Coldcard hardware wallets that has been associated with over $100 million in verified losses. Both security breaches have impacted Bitcoin-related software infrastructure rather than the fundamental Bitcoin network protocol itself.
BTCPay has explicitly stated that these two security incidents are completely separate and unrelated. Nevertheless, the combined security concerns surrounding Bitcoin infrastructure tools have heightened vigilance among operators throughout the ecosystem.
BTCPay has indicated its intention to restore remote access capabilities following a comprehensive security assessment, though no specific timeframe has been announced.
All operators are strongly encouraged to deploy the security update without delay and conduct comprehensive reviews of their node activity for any indicators of unauthorized access or compromise.





