Key Points
- BTCPay Server suspended remote external access to Lightning Network nodes following the exploitation of a severe security vulnerability
- Hackers acquired “macaroon” authentication files that control LND nodes, enabling unauthorized fund transfers
- The newly released version 2.4.2 fixes the security gap and automatically refreshes credentials for typical setups
- Foundation’s CEO Zach Herbert verified that his organization’s Lightning node was emptied during the night
- Citadel21, a Bitcoin media outlet, likewise reported having its Lightning node drained, with neither party revealing specific loss figures
BTCPay Server has implemented an emergency suspension of public remote access to Lightning Network nodes following a critical security breach that enabled attackers to siphon funds from a minimum of two node operators.
The security incident specifically targeted systems operating Lightning Network Daemon infrastructure. Cybercriminals leveraged the weakness to acquire “macaroon” authentication credentialsāspecialized files that grant control authority over LND nodes. With these credentials in hand, the attackers gained unrestricted capability to transfer funds.
The implemented safeguard blocks third-party wallet applications such as Zeus from establishing connections via BTCPay Server domains or Tor onion addresses on Docker-based deployments. Despite these restrictions, BTCPay clarified that Lightning payment functionality remains operational and promised to reinstate remote access capabilities once security protocols are verified as safe.
Patch Details and Functions
BTCPay launched version 2.4.2 as a remediation measure for the vulnerability. This release incorporates LND version 0.21.1 and executes automatic regeneration of macaroon authentication credentials for conventional installations.
Node operators who channel LND traffic through custom reverse proxies, self-managed Tor services, or independently configured port forwarding external to BTCPay must manually rotate their authentication credentials. The security patch does not affect access pathways that operators have established outside of BTCPay’s default configuration.
BTCPay recommended that all node operators conduct thorough audits for suspicious payment activity, unexpected channel closures, unknown peer connections, and any irregularities in balances across both onchain and Lightning accounts.
Confirmed Breach Victims
Zach Herbert, Chief Executive Officer of Foundation, openly acknowledged that his organization’s Lightning node suffered a complete drain during overnight hours. He subsequently provided clarification that the company’s hot wallet infrastructure remained secure and unaffected by the breach. The Lightning channels were forcibly closed and associated funds were withdrawn by the attackers.
Bitcoin-focused publication Citadel21 similarly confirmed that its Lightning node experienced a complete fund sweep. Neither affected organization has publicly disclosed the exact monetary value of stolen assets.
The complete scope of affected node operators throughout the ecosystem has not been determined.
This security event arrives in the wake of a distinct Coldcard hardware wallet vulnerability that has been associated with verified losses exceeding $100 million. Both security incidents targeted Bitcoin-adjacent software and infrastructure rather than Bitcoin’s core protocol layer.
BTCPay emphasized that these two security incidents are completely separate and unrelated. Nevertheless, the combined security challenges affecting Bitcoin infrastructure solutions have heightened vigilance among operators across the ecosystem.
BTCPay indicated its intention to reinstate remote access features following comprehensive security validation. No specific timeframe for restoration has been announced.
All operators are strongly encouraged to deploy the security update without delay and conduct comprehensive reviews of node activity to identify potential indicators of unauthorized access or compromise.


