Bitcoin infrastructure exploit drains merchant Lightning nodes

1 hour ago 19

BTCPay Server, the open-source payment processor used by thousands of Bitcoin merchants worldwide, issued an urgent security alert on August 7 after attackers exploited a critical vulnerability to drain funds from connected Lightning nodes. The flaw gave unauthorized access to Lightning node credentials, and at least two prominent Bitcoin community members confirmed their nodes were emptied overnight.

Foundation, the company behind a popular line of hardware wallets, and hodlonaut, who runs the Bitcoin publication Citadel21, both reported that their Lightning channels were force-closed and funds swept clean. Their associated hot wallets were not affected, which narrows the attack vector to something specific about how BTCPay Server handled Lightning node authentication.

What went wrong

The vulnerability centered on Lightning node credentials known as macaroons, which function like API keys that grant permission to perform actions on a Lightning node. The problem was that these credentials persisted even after users applied previous software updates. Operators who had dutifully updated their BTCPay Server installations were still exposed because the old macaroons remained valid and required a manual credential refresh.

BTCPay Server released version 2.4.2 on the same day as the alert, along with guidance to upgrade its NBXplorer backend to version 2.6.10. The project told all operators to either update immediately or shut down their servers entirely to prevent further losses.

Notably, this vulnerability was separate from a prior authentication bug that BTCPay Server had already patched just days earlier.

The self-hosting paradox

Foundation builds hardware wallets, devices explicitly designed to give users maximum control over their own Bitcoin. That even they were caught off guard by a BTCPay Server exploit illustrates how demanding it is to maintain airtight security across every layer of a self-hosted stack.

The attack also arrives during a period of heightened scrutiny for Bitcoin infrastructure more broadly. A recent Coldcard firmware flaw put hardware wallet security under the microscope, and the Bitcoin Red Team has been conducting AI-assisted audits of critical Bitcoin tools. The fact that this BTCPay vulnerability was actively exploited before it could be caught by those auditing efforts raises questions about how well the current security review process is keeping pace with the attack surface.

Fallout and what to watch

Both BTCPay Server and the Bitcoin Red Team have indicated that detailed technical analyses of the exploit will be published in the coming days.

The specific mechanics of this exploit, credentials that survived software updates, point to a category of vulnerability that’s easy to overlook. When the fix requires an additional manual step that isn’t immediately obvious, the gap between “updated” and “secure” becomes a hunting ground for attackers.

Merchants still running older versions of BTCPay Server with Lightning enabled should treat the situation as urgent. The project’s recommendation to shut down servers if an immediate update isn’t possible is unusually blunt for open-source maintainers.

Disclosure: This article was edited by Editorial Team. For more information on how we create and review content, see our Editorial Policy.

Read Entire Article