Fresh Lightning Attack Exposes Weakness, Empties Payment Nodes

BTCPay has urged users running LND to update immediately or shut down their servers after attackers obtained credentials that can control Lightning wallets and move funds.

A difficult stretch for Bitcoin infrastructure has taken another hit, this time impacting merchants who accept BTC through the Lightning Network, a layer designed for fast and inexpensive payments.

Late Friday, attackers exploited a critical flaw affecting BTCPay Server setups, exposing credentials tied to Lightning nodes and allowing funds to be drained, the team said in a post on X.

BTCPay confirmed that funds were stolen and advised all LND users — the most widely used Lightning node software — to upgrade to version 2.4.2 or take their systems offline as a precaution.

The project has not yet disclosed how many users were affected or the total losses.

The vulnerability allowed unauthenticated remote attackers to access “.macaroon” files, which function as permission keys for interacting with an LND node. With these credentials, attackers could take over nodes and transfer funds.

Hardware wallet firm Foundation was among the affected parties. CEO Zach Herbert said attackers emptied the company’s BTCPay Lightning node overnight, closing channels and withdrawing funds, while its on-chain hot wallet remained untouched.

Bitcoin publication Citadel21, run by pseudonymous commentator hodlonaut, also reported that its Lightning node had been drained, though it said only a small amount was involved.

The issue had already been reported to BTCPay by members of the Bitcoin Red Team — a group of developers using AI tools to scan bitcoin codebases — which has identified thousands of vulnerabilities across hundreds of projects.

BTCPay credited contributors Craig Raw, Rob Hamilton, Calle, and Evan Kaloudis for responsibly disclosing the flaw and assisting with its analysis.

The group said it moved quickly to publish its findings because others were likely to discover the same vulnerability. By the time BTCPay issued its public warning, attackers were already exploiting it on live systems.

Following its initial alert, BTCPay clarified that its standard on-chain wallets, including hot wallets generated within the platform, are not affected.

The vulnerability is specific to setups using LND. However, funds held in LND’s own on-chain wallet may still be at risk, as they are tied to the compromised Lightning node.

BTCPay has not yet released full technical details, noting that operators need time to secure their systems. A detailed postmortem is expected in the coming days.