Updated 4 min agoPublished 5 min ago
2 min read

Summary
- Attackers exploited a critical vulnerability in BTCPay Server to steal funds from Lightning nodes running LND, prompting urgent calls to update to version 2.4.2 or take servers offline.
- The flaw allowed unauthenticated access to LND “.macaroon” credential files, enabling attackers to seize control of affected Lightning nodes and drain their channels, though BTCPay’s standard on-chain wallets were not impacted.
- Victims including hardware-wallet maker Foundation and bitcoin publication Citadel21 reported their Lightning nodes were swept, as BTCPay and the Bitcoin Red Team investigate and prepare a full postmortem on the incident.
A rough week for bitcoin's software is getting worse, this time hitting merchants who accept bitcoin BTC$64,968.63 payments through Lightning, a separate network built on top of bitcoin for instant, low-cost transfers.
Attackers drained Lightning nodes running behind BTCPay Server late on Friday after exploiting a critical vulnerability that exposed the credentials protecting them, the team said in an X post.
BTCPay confirmed funds were stolen and told anyone running LND, the most widely used software for operating a Lightning node, to update immediately to version 2.4.2 or take the server offline.
The project has not disclosed how many users were hit or how much bitcoin was taken.
The flaw allowed an unauthenticated remote attacker to obtain “.macaroon” files, or credentials that give software permission to interact with an LND Lightning node. BTCPay said the attacks it reviewed targeted those files, which could then be used to take control of the node and move funds.
Hardware-wallet maker Foundation was among the victims. Chief Executive Zach Herbert said attackers drained the company's BTCPay Lightning node overnight, closing its channels and sweeping the funds. Its BTCPay on-chain hot wallet was untouched.
Citadel21, the bitcoin publication run by pseudonymous commentator hodlonaut, also reported that its Lightning node had been swept, though it said little money was held there.
The vulnerability had already been reported to BTCPay by members of the Bitcoin Red Team — a group of developers that began pointing AI models at bitcoin codebases this week and has filed thousands of findings across hundreds of projects since.
Read More: Bitcoin developers flag 85 critical bugs in an "extremely bad" situation.
BTCPay credited Red Team members Craig Raw, Rob Hamilton, Calle and Evan Kaloudis with responsibly disclosing the issue and helping analyze it.
The group's stated reason for publishing findings quickly was that people outside it would arrive at the same bugs, and by the time BTCPay's public warning went out, attackers were already exploiting this one against live servers.
Meanwhile, BTCPay narrowed the scope after its initial alert, saying its standard on-chain wallets, including hot wallets generated inside BTCPay, are not affected by the credential flaw.
The exposure applies specifically to deployments using LND, and funds held inside LND's own on-chain wallet can still be at risk because they sit under the compromised Lightning node.
BTCPay has not yet published technical details of the vulnerability, saying operators need time to patch. A full postmortem is due in the coming days.
Related Assets
- 1
- 2
- 3
- 4
- 5
- 6
- 7
- 8
- 9
- 10
Building the Zcash Machine: Tachyon and Quantum Readiness

Building the Zcash Machine: Tachyon and Quantum Readiness
Zcash’s Tachyon upgrade aims to scale shielded payments, improve quantum readiness, and test whether its funding, security, and governance can hold.
Jun 30, 2026
Zcash’s Tachyon upgrade aims to scale shielded payments, improve quantum readiness, and test whether its funding, security, and governance can hold.
Why it matters:
Zcash’s Tachyon upgrade aims to scale shielded payments, improve quantum readiness, and test whether its funding, security, and governance can hold.