BTCPay Server Restricts Remote Lightning Access Following Vulnerability Exploitation
A critical vulnerability in BTCPay Server enabled attackers to steal Lightning Network credentials and drain funds from at least two operators before the service restricted remote access.
Attackers Exploited Credentials to Drain Node Funds
The vulnerability enabled unauthenticated remote attackers to access macaroon credential files, which serve as the primary keys to managing Lightning Network Daemon (LND) nodes. Once obtained, these credentials granted attackers the ability to seize control of Lightning nodes and transfer their funds. The exploit has already claimed at least two known victims in the cryptocurrency space. Foundation, a hardware-wallet company, reported that its Lightning node was compromised and drained overnight, though its hot wallet remained protected. The company’s CEO, Zach Herbert, later clarified that while the hot wallet stayed secure, the organization’s Lightning channels were forcibly closed and their funds swept away. Similarly, Bitcoin publication Citadel21 disclosed that its Lightning node fell victim to the same attack and was emptied. Despite these confirmed losses, neither operator has revealed the amounts stolen, and the total damage and complete number of affected operators remain unknown.
BTCPay Implements Temporary Access Restrictions
To prevent further exploitation, BTCPay Server has restricted public remote connections to LND-based Lightning nodes. External wallets such as Zeus can no longer connect through BTCPay Server domains or Tor onion addresses on Docker deployments during this restriction period. Importantly, BTCPay clarified that Lightning Network payments can continue functioning normally, ensuring the service remains operational for transactions despite the access limitations. Version 2.4.2 of BTCPay now bundles LND version 0.21.1 and automatically regenerates macaroon credentials on standard installations, effectively invalidating any credentials that attackers may have compromised. The organization has committed to restoring remote-access functionality once it determines the environment is secure, signaling that this restriction is temporary rather than permanent.
Operators Must Audit and Update Their Systems
All operators managing Lightning nodes through BTCPay have been advised to conduct comprehensive security reviews of their systems. BTCPay recommends checking for unauthorized payments, unexpected channel closures, unfamiliar peer connections, and any discrepancies between recorded balances and actual onchain or Lightning balance confirmations. A critical note for operators using alternative infrastructure: those who manage LND through independent reverse proxies, Tor services, forwarded ports, or other routes outside BTCPay must manually rotate their credentials, as the automatic credential regeneration in Version 2.4.2 only applies to standard BTCPay installations.
This incident follows a recent Coldcard hardware-wallet vulnerability responsible for more than $100 million in confirmed losses. While both incidents affected software surrounding Bitcoin rather than Bitcoin’s core protocol, they underscore the importance of security vigilance across the cryptocurrency ecosystem and the need for users to stay current with security patches. Security vulnerabilities in widely-used Bitcoin infrastructure serve as a reminder that robust security practices remain critical throughout the broader crypto ecosystem.
Source: Cointelegraph. Not financial advice.