Home Cryptocurrency SKN | BTCPay Restricts Remote Lightning Access After Attackers Steal Funds
Cryptocurrency

SKN | BTCPay Restricts Remote Lightning Access After Attackers Steal Funds

Share
Share

BTCPay Server has temporarily restricted public remote connections to Lightning Network nodes running Lightning Network Daemon (LND) after attackers exploited a critical vulnerability that exposed credentials and enabled the movement of funds. The project said the restriction affects external wallets connecting through BTCPay Server domains or Tor onion addresses on Docker deployments, while Lightning payments remain operational. At least two operators, Foundation and Bitcoin publication Citadel21, have publicly reported that their Lightning nodes were drained, although the total amount stolen and the number of affected operators remain unknown.

BTCPay Restricts Remote Lightning Connections

BTCPay Server has temporarily disabled public remote access to Lightning Network nodes running LND after a security vulnerability was exploited by attackers.

The restriction prevents external wallets, including Zeus, from connecting to LND nodes through a BTCPay Server domain or Tor onion address when using Docker deployments.

BTCPay said Lightning payments can continue operating despite the restriction and that remote access will be restored once the project determines that the connection method can be safely re-enabled.

Critical Vulnerability Exposed LND Credentials

According to BTCPay’s security advisory, the vulnerability allowed an unauthenticated remote attacker to obtain “macaroon” credential files used to control LND, a major implementation of the Lightning Network.

An attacker who obtained the exposed credentials could potentially take control of an affected Lightning node and move funds held by the node.

The incident highlights the security risks associated with remote access to Lightning infrastructure, particularly when credentials capable of controlling node operations become exposed.

BTCPay Releases Security Update

BTCPay has released version 2.4.2, which installs LND version 0.21.1 and automatically regenerates macaroon credentials on standard BTCPay installations.

The project is advising operators to review their nodes for unauthorized payments, unexpected channel closures, unfamiliar peers and discrepancies between recorded balances and their actual onchain or Lightning balances.

Operators who expose LND through their own reverse proxy, Tor service, forwarded port or another access method outside BTCPay’s standard configuration must rotate their credentials separately.

Installing the BTCPay update does not automatically close independently managed access routes, meaning operators with customized infrastructure must take additional security measures.

Operators Report Lightning Losses

At least two operators have publicly confirmed that their Lightning nodes were affected.

Foundation CEO Zach Herbert said the hardware wallet company’s Lightning node was drained overnight. He later clarified that Foundation’s hot wallet was not affected, while its Lightning channels were closed and the funds were swept.

Bitcoin publication Citadel21 also reported that its Lightning node had been swept.

Neither organization disclosed the amount of Bitcoin lost, leaving the total financial impact of the incident unclear.

Latest in Series of Bitcoin Security Incidents

The BTCPay incident comes amid heightened concern over security vulnerabilities affecting Bitcoin-related infrastructure.

The recent Coldcard hardware wallet vulnerability, for example, has been linked to more than $100 million in confirmed Bitcoin losses.

The two incidents are separate and did not compromise Bitcoin’s underlying protocol. Instead, they affected software and hardware products used to interact with the Bitcoin network.

The incidents nevertheless highlight the importance of securing the infrastructure surrounding Bitcoin, particularly as Lightning Network adoption increases and more funds are held in payment channels.

Lightning Security Under Pressure

The Lightning Network is designed to enable faster and lower-cost Bitcoin transactions by allowing users to conduct payments through offchain channels.

However, operating Lightning nodes requires users and businesses to manage additional infrastructure, credentials and liquidity. Vulnerabilities affecting node software can therefore expose funds even when the underlying Bitcoin network remains secure.

BTCPay’s decision to temporarily restrict remote access demonstrates the trade-off between convenience and security as businesses rely on Lightning infrastructure for payments.

Closing Insights

The BTCPay Server incident underscores the growing importance of security across Bitcoin’s expanding infrastructure layer. While the underlying Bitcoin protocol was not compromised, vulnerabilities in Lightning node software and remote-access configurations can still create significant risks for operators holding funds. The rapid release of BTCPay’s security update and temporary restriction of remote connections demonstrate the need for operators to maintain updated software, rotate credentials and closely monitor Lightning activity as the network continues to develop.

Comparison, examination, and analysis between investment houses

Leave your details, and an expert from our team will get back to you as soon as possible

    Share

    Don't Miss

    SKN | Ondo Enables Institutions to Convert Stocks Directly Into Tokenized Shares

    Key Takeaways Ondo Finance has introduced in-kind conversion, allowing approved institutions to exchange existing stocks and ETFs directly for tokenized versions without using...

    SKN | US Prosecutors Probe Binance Over Iran Sanctions Compliance as Bitcoin Rebounds

    Key Takeaways Manhattan federal prosecutors are investigating whether Binance knowingly allowed trading that may have violated US sanctions on Iran. The Justice Department’s...

    Related Articles

    SKN | Solana Foundation Hires Former Binance CMO and Payments Executive as Partnerships Expand

    Key Points: The Solana Foundation appointed former Binance Chief Marketing Officer Rachel...

    SKN | Institutions Held Crypto Through 50% Drawdown, Bitwise Finds

    Key Points: All 15 institutions interviewed by Bitwise said they maintained their...

    SKN | Bitcoin ETFs Add $347 Million as BTC Falls Below $84,000 After Topping $87,000

    Key Points: US spot Bitcoin ETFs recorded approximately $347 million in net...

    SKN | ESMA to Prioritize AI and Tokenization Supervision Across EU Financial Markets in 2027

    Key Points: ESMA will make artificial intelligence and tokenization the initial focus...

    Investcoin

    GET A FREE, EXPERT-BACKED
    INVESTMENT COMPARISON TODAY