Bitcoin’s infrastructure ecosystem suffered another security blow this week when attackers exploited a critical vulnerability in BTCPay Server to drain funds from Lightning network nodes. According to reporting by CoinDesk, the flaw exposed credential files that gave attackers full control over affected merchant nodes running LND, the most widely deployed Lightning node software.
The vulnerability allowed unauthenticated remote attackers to access “.macaroon” files — cryptographic credentials that control Lightning wallets and authorize fund movements. BTCPay issued an urgent advisory Friday night, instructing all LND operators to update immediately to version 2.4.2 or take their servers offline. The project has not yet disclosed the total number of affected users or the aggregate amount of Bitcoin stolen.
Merchants caught in the crossfire
High-profile casualties emerged quickly. Foundation, a hardware wallet manufacturer, reported that attackers drained its BTCPay Lightning node overnight, closing channels and sweeping the funds. The company’s on-chain hot wallet stored within BTCPay remained untouched, suggesting the vulnerability targeted Lightning-specific infrastructure. Citadel21, a Bitcoin publication, also confirmed its Lightning node was compromised, though the operator indicated only a modest amount was held there at the time.
The incident strikes at a critical junction in Bitcoin’s payment layer. The Lightning network promises instant, near-costless transactions — a core value proposition for merchants adopting Bitcoin payments. Yet the infrastructure supporting those payments remains fragile, particularly when integrated with third-party server software like BTCPay.
How the attack unfolded
Attackers exploited the credential exposure to take direct control of LND nodes and move funds without authorization. BTCPay noted that its standard on-chain wallets were not affected by the flaw, but any Bitcoin held in the LND node’s own on-chain wallet remained at risk because it sits beneath the compromised Lightning infrastructure. The distinction matters: attackers could drain Lightning channels but not BTCPay’s core wallet architecture.
The Bitcoin Red Team, a group of developers who recently began scanning Bitcoin codebases with AI models, had already reported this vulnerability to BTCPay responsibly. Members including Craig Raw, Rob Hamilton, Calle and Evan Kaloudis helped analyze the issue before public disclosure. However, the Red Team’s rapid approach to publishing findings — driven by the logic that external attackers will discover bugs anyway — appears vindicated by the fact that live exploitation began before BTCPay’s warning circulated widely.
Broader implications for Bitcoin infrastructure
This marks another chapter in a difficult week for Bitcoin software. The incident underscores the security risks facing payment processors and node operators who depend on third-party software stacks. While Lightning was designed to improve Bitcoin’s scalability and merchant adoption, its operational complexity introduces new attack surfaces that users must actively manage.
BTCPay has not yet published technical details, prioritizing time for operators to patch. A full postmortem is expected in the coming days. Until then, merchants running LND-backed Lightning nodes face a stark choice: update immediately or take their payment infrastructure offline.