en
Back to the list

Another Bitcoin infrastructure exploit hits, this time draining Lightning payment servers

source-logo  coindesk.com 2 h
image

A rough week for bitcoin's software is getting worse, this time hitting merchants who accept bitcoin $BTC$64,968.63 payments through Lightning, a separate network built on top of bitcoin for instant, low-cost transfers.

Attackers drained Lightning nodes running behind BTCPay Server late on Friday after exploiting a critical vulnerability that exposed the credentials protecting them, the team said in an X post.

BTCPay confirmed funds were stolen and told anyone running LND, the most widely used software for operating a Lightning node, to update immediately to version 2.4.2 or take the server offline.

The project has not disclosed how many users were hit or how much bitcoin was taken.

The flaw allowed an unauthenticated remote attacker to obtain “.macaroon” files, or credentials that give software permission to interact with an LND Lightning node. BTCPay said the attacks it reviewed targeted those files, which could then be used to take control of the node and move funds.

Hardware-wallet maker Foundation was among the victims. Chief Executive Zach Herbert said attackers drained the company's BTCPay Lightning node overnight, closing its channels and sweeping the funds. Its BTCPay on-chain hot wallet was untouched.

Citadel21, the bitcoin publication run by pseudonymous commentator hodlonaut, also reported that its Lightning node had been swept, though it said little money was held there.

The vulnerability had already been reported to BTCPay by members of the Bitcoin Red Team — a group of developers that began pointing AI models at bitcoin codebases this week and has filed thousands of findings across hundreds of projects since.

Read More: Bitcoin developers flag 85 critical bugs in an "extremely bad" situation.

BTCPay credited Red Team members Craig Raw, Rob Hamilton, Calle and Evan Kaloudis with responsibly disclosing the issue and helping analyze it.

The group's stated reason for publishing findings quickly was that people outside it would arrive at the same bugs, and by the time BTCPay's public warning went out, attackers were already exploiting this one against live servers.

Meanwhile, BTCPay narrowed the scope after its initial alert, saying its standard on-chain wallets, including hot wallets generated inside BTCPay, are not affected by the credential flaw.

The exposure applies specifically to deployments using LND, and funds held inside LND's own on-chain wallet can still be at risk because they sit under the compromised Lightning node.

BTCPay has not yet published technical details of the vulnerability, saying operators need time to patch. A full postmortem is due in the coming days.

coindesk.com