Open account

Bitcoin Lightning Nodes Drained as Attackers Exploit BTCPay Vulnerability

BTCPay Server disclosed a critical vulnerability affecting every version before 2.4.2 that exposed LND credential files and allowed unauthenticated attackers to take over Lightning nodes and steal funds. The issue is a security incident for Bitcoin infrastructure rather than a price-driven market catalyst, but it may heighten caution around self-hosted payment processors and Lightning Network custody risks. BTCPay said its on-chain wallets, including hot wallets, were not affected, though funds in compromised LND on-chain wallets remain at risk until credentials are rotated. At least two operators publicly reported losses: Foundation said its Lightning node was drained overnight, while Citadel21 said its node was swept, though it held little. The disclosure came alongside mention of broader Bitcoin security concerns, including a recent Coldcard firmware flaw tied to more than $100 million in confirmed losses.

Category

Bitcoin

Sentiment

Bearish

Event

Security incident

Reading time

1 min