BTCPay locks the front door after Lightning macaroons got nibbled 🍪
Back to feed

BTCPay locks the front door after Lightning macaroons got nibbled 🍪

BTCPay Server has temporarily blocked public remote connections to Lightning Network nodes running Lightning Network Daemon (LND) software after attackers exploited a critical vulnerability to obtain node credentials and move funds. The restriction prevents external wallets such as Zeus from connecting through a BTCPay Server domain or Tor onion address on Docker deployments. BTCPay said Lightning payments can continue and that it plans to restore the remote-access option when it considers it safe.

The vulnerability allowed an unauthenticated remote attacker to obtain "macaroon" credential files used to control LND, an implementation of the Lightning Network, according to the project's security advisory. The exposed credentials could let attackers take control of an LND node and move its funds. BTCPay said version 2.4.2 installs LND version 0.21.1 and automatically regenerates macaroon credentials on standard BTCPay installations. The project advised operators to check for unauthorized payments, unexpected channel closures, unfamiliar peers and discrepancies between their records and onchain or Lightning balances. BTCPay also said operators exposing LND through their own reverse proxy, Tor service, forwarded port, or another route outside BTCPay must rotate their credentials separately, and that installing the update does not close access routes managed independently by the operator.

At least two operators publicly reported losses. Foundation CEO Zach Herbert said the hardware-wallet company's Lightning node was drained overnight, later clarifying that its hot wallet was unaffected while its Lightning channels were closed and the funds swept. Bitcoin publication Citadel21 also reported that its Lightning node had been swept. Neither operator disclosed the amount lost.

The BTCPay breach is the latest security incident involving widely used Bitcoin products, following a Coldcard hardware-wallet flaw linked to more than $100 million in confirmed losses, with related reporting putting July losses at $247M and the second-worst month of 2026. The separate incidents affected software surrounding Bitcoin rather than the network's underlying protocol.

Mentioned Coins

$BTC
Share:
Publishercryptonewsroom.xyz
Published
CategorySecurity

Disclaimer: This content is for information and entertainment purposes only. It does not constitute financial, investment, legal, or tax advice. Always do your own research and consult with qualified professionals before making any financial decisions.

See our Terms of Service, Privacy Policy, and Editorial Policy.