BTCPay Server has temporarily restricted public remote connections to Lightning Network nodes running Lightning Network Daemon (LND) after attackers exploited a critical vulnerability that exposed credentials and enabled the movement of funds. The project said the restriction affects external wallets connecting through BTCPay Server domains or Tor onion addresses on Docker deployments, while Lightning payments remain operational. At least two operators, Foundation and Bitcoin publication Citadel21, have publicly reported that their Lightning nodes were drained, although the total amount stolen and the number of affected operators remain unknown.
BTCPay Restricts Remote Lightning Connections
BTCPay Server has temporarily disabled public remote access to Lightning Network nodes running LND after a security vulnerability was exploited by attackers.
The restriction prevents external wallets, including Zeus, from connecting to LND nodes through a BTCPay Server domain or Tor onion address when using Docker deployments.
BTCPay said Lightning payments can continue operating despite the restriction and that remote access will be restored once the project determines that the connection method can be safely re-enabled.
Critical Vulnerability Exposed LND Credentials
According to BTCPay’s security advisory, the vulnerability allowed an unauthenticated remote attacker to obtain “macaroon” credential files used to control LND, a major implementation of the Lightning Network.
An attacker who obtained the exposed credentials could potentially take control of an affected Lightning node and move funds held by the node.
The incident highlights the security risks associated with remote access to Lightning infrastructure, particularly when credentials capable of controlling node operations become exposed.
BTCPay Releases Security Update
BTCPay has released version 2.4.2, which installs LND version 0.21.1 and automatically regenerates macaroon credentials on standard BTCPay installations.
The project is advising operators to review their nodes for unauthorized payments, unexpected channel closures, unfamiliar peers and discrepancies between recorded balances and their actual onchain or Lightning balances.
Operators who expose LND through their own reverse proxy, Tor service, forwarded port or another access method outside BTCPay’s standard configuration must rotate their credentials separately.
Installing the BTCPay update does not automatically close independently managed access routes, meaning operators with customized infrastructure must take additional security measures.
Operators Report Lightning Losses
At least two operators have publicly confirmed that their Lightning nodes were affected.
Foundation CEO Zach Herbert said the hardware wallet company’s Lightning node was drained overnight. He later clarified that Foundation’s hot wallet was not affected, while its Lightning channels were closed and the funds were swept.
Bitcoin publication Citadel21 also reported that its Lightning node had been swept.
Neither organization disclosed the amount of Bitcoin lost, leaving the total financial impact of the incident unclear.
Latest in Series of Bitcoin Security Incidents
The BTCPay incident comes amid heightened concern over security vulnerabilities affecting Bitcoin-related infrastructure.
The recent Coldcard hardware wallet vulnerability, for example, has been linked to more than $100 million in confirmed Bitcoin losses.
The two incidents are separate and did not compromise Bitcoin’s underlying protocol. Instead, they affected software and hardware products used to interact with the Bitcoin network.
The incidents nevertheless highlight the importance of securing the infrastructure surrounding Bitcoin, particularly as Lightning Network adoption increases and more funds are held in payment channels.
Lightning Security Under Pressure
The Lightning Network is designed to enable faster and lower-cost Bitcoin transactions by allowing users to conduct payments through offchain channels.
However, operating Lightning nodes requires users and businesses to manage additional infrastructure, credentials and liquidity. Vulnerabilities affecting node software can therefore expose funds even when the underlying Bitcoin network remains secure.
BTCPay’s decision to temporarily restrict remote access demonstrates the trade-off between convenience and security as businesses rely on Lightning infrastructure for payments.
Closing Insights
The BTCPay Server incident underscores the growing importance of security across Bitcoin’s expanding infrastructure layer. While the underlying Bitcoin protocol was not compromised, vulnerabilities in Lightning node software and remote-access configurations can still create significant risks for operators holding funds. The rapid release of BTCPay’s security update and temporary restriction of remote connections demonstrate the need for operators to maintain updated software, rotate credentials and closely monitor Lightning activity as the network continues to develop.
Comparison, examination, and analysis between investment houses
Leave your details, and an expert from our team will get back to you as soon as possible