Key Takeaways
- A severe vulnerability in BTCPay Server enabled unauthorized access to Lightning nodes powered by LND software, resulting in fund theft
- Attackers gained access by stealing exposed “.macaroon” authentication files, granting them complete control over Lightning wallets
- BTCPay Server issued an emergency advisory requiring all installations to upgrade to version 2.4.2 or power down completely
- Confirmed victims include hardware wallet manufacturer Foundation and Bitcoin media outlet Citadel21, both reporting drained Lightning nodes
- Despite responsible disclosure from the Bitcoin Red Team, malicious actors had already begun exploiting the weakness before public notification
A severe security breach in BTCPay Server emerged Friday evening, enabling malicious actors to siphon Bitcoin from Lightning Network nodes and prompting emergency warnings for users to either update their systems or take them offline immediately.
BTCPay Server operates as a self-hosted, open-source payment processing platform that enables merchants and enterprises to receive Bitcoin transactions while maintaining complete custody of their funds.
The Nature of the Vulnerability
The security weakness permitted unauthorized remote access to “.macaroon” authentication files. These credentials function as access tokens that authorize applications to communicate with Lightning Network Daemon (LND) nodes.
LND represents the predominant implementation for operating Lightning Network infrastructure. With these credential files in hand, bad actors could assume complete authority over affected nodes and redirect funds to their own wallets.
BTCPay acknowledged the theft of user funds and issued an urgent directive for all users to implement version 2.4.2 without delay. Systems unable to receive the update were instructed to cease operations completely pending patch deployment.
The development team has not revealed the exact number of compromised installations or quantified the total Bitcoin losses.
Foundation, a hardware wallet manufacturer, verified that its BTCPay Lightning infrastructure was completely drained during the overnight hours. Chief Executive Officer Zach Herbert explained that attackers force-closed the company’s payment channels and transferred all available funds. The company’s on-chain hot storage remained uncompromised.
Bitcoin media platform Citadel21, operated by pseudonymous commentator hodlonaut, likewise acknowledged its Lightning node was emptied, though reported minimal funds were at risk during the incident.
BTCPay emphasized that conventional on-chain Bitcoin wallets integrated within BTCPay installations are not vulnerable to this specific credential exposure. Nevertheless, any Bitcoin held in LND’s internal on-chain wallet structure remains compromised because these funds fall under the control of the affected node infrastructure.
Post-Update Security Procedures
Following successful installation of the security patch, BTCPay recommended users implement several protective measures: regenerate all macaroon credential files and the associated database, change all authentication tokens connected to Lightning Network backend systems, and transfer Bitcoin from existing hot wallets created through BTCPay before establishing replacement wallets.
These protective actions are designed to invalidate any credentials potentially obtained by attackers during the exposure window.
Discovery and Disclosure Timeline
The Bitcoin Red Team, a developer collective that recently commenced automated security analysis of Bitcoin software using artificial intelligence models, submitted a confidential vulnerability report to BTCPay. Security researchers Craig Raw, Rob Hamilton, Calle, and Evan Kaloudis received recognition for their responsible disclosure practices.
The research group stated it accelerated publication because independent attackers would probably identify identical vulnerabilities on their own. Evidence suggests malicious exploitation had already commenced before BTCPay’s public security alert was distributed.
BTCPay has withheld comprehensive technical specifications of the vulnerability to date. A detailed incident analysis is anticipated within the next several days.


