BTC/USD $68,420 +2.8%
ETH/USD $3,540 +1.4%
SOL/USD $142.80 -0.6%
BNB/USD $605.20 +0.9%
XRP/USD $0.62 -1.2%
DOGE/USD $0.18 +5.4%
BTC/USD $68,420 +2.8%
ETH/USD $3,540 +1.4%
SOL/USD $142.80 -0.6%
BNB/USD $605.20 +0.9%
XRP/USD $0.62 -1.2%
DOGE/USD $0.18 +5.4%
Bitcoin

BTCPay Server Flaw Lets Attackers Steal Lightning Node…

What Happened To BTCPay Server Lightning Nodes? BTCPay Server has temporarily restricted public remote connections to Lightning Network nodes running Lightning Network Daemon software after a

AnonymousCryptoCompass newsroom
August 9, 2026
4 min read
NEWS
Hero article visual / chart / editorial image
CryptoCompass editorial visual for bitcoin coverage.

AFX Scrambles After $24M Hack Traced to One Dev

What Happened To BTCPay Server Lightning Nodes?

BTCPay Server has temporarily restricted public remote connections to Lightning Network nodes running Lightning Network Daemon software after attackers exploited a critical vulnerability that exposed credentials used to control affected nodes and move funds. The restriction prevents external wallets such as Zeus from connecting through a BTCPay Server domain or Tor onion address on Docker deployments. BTCPay said Lightning payments can continue, meaning the measure is focused on remote node access rather than disabling Lightning functionality altogether. The vulnerability exposed files known as macaroons, credentials that grant access to LND functions. BTCPay said an unauthenticated remote attacker could obtain those credentials and potentially take control of a node, allowing funds to be transferred without the operator’s authorization. At least two operators publicly reported losses. Foundation CEO Zach Herbert said the hardware-wallet company’s Lightning node was drained overnight. He later said its hot wallet was not affected, while its Lightning channels were closed and the funds swept. Bitcoin publication Citadel21 also reported that its Lightning node had been swept. Neither disclosed the amount lost.

How Does Version 2.4.2 Protect Operators?

BTCPay Server released version 2.4.2, which installs LND version 0.21.1 and automatically regenerates macaroon credentials on standard BTCPay deployments. Rotating the credentials invalidates previously exposed access files and helps prevent attackers from continuing to use stolen credentials after operators update. BTCPay advised users to review their nodes for unauthorized Lightning payments, unexpected channel closures, unfamiliar peers and differences between expected balances and funds visible onchain or through Lightning. The automatic credential rotation does not cover every configuration. Operators who expose LND through their own reverse proxy, Tor service, forwarded port or another access route outside BTCPay must rotate credentials separately. Installing version 2.4.2 does not close remote connections that an administrator created independently of BTCPay’s standard setup. That distinction matters because operators may assume an application update has removed all exposure when separate networking rules remain active. BTCPay’s response therefore requires users with custom deployments to review both their credentials and how their nodes are reachable from the internet.

Investor Takeaway

The incident did not compromise Bitcoin’s underlying network. The risk came from software and credentials used around Lightning infrastructure, reinforcing the difference between protocol security and the security of applications, wallets and node-management tools built on top of Bitcoin.

Why Is Remote Lightning Access Being Disabled?

Remote access is useful because operators can manage Lightning nodes from mobile wallets and other external tools without directly logging into the server. The same feature becomes dangerous when credentials capable of controlling the node can be retrieved by an attacker. BTCPay’s temporary restriction reduces the number of publicly reachable paths while developers determine when the feature can be restored safely. The project has not indicated that Lightning payments themselves need to stop, allowing merchants and other users to continue processing transactions while limiting remote administrative access. The response also shows why credential management is especially important for Lightning nodes. Unlike a watch-only interface, administrative credentials can permit actions involving channels and funds. If those credentials are stolen, an attacker may not need to compromise the operator’s hardware wallet or obtain a seed phrase to cause losses within the Lightning environment.

What Does The Exploit Mean For Bitcoin Security?

The BTCPay incident follows another security problem involving a widely used Bitcoin product, after a Coldcard hardware-wallet flaw was linked to more than $100 million in confirmed losses. The incidents were separate and affected products surrounding Bitcoin rather than flaws in Bitcoin’s consensus or transaction protocol. That difference is important for users assessing security risk. Bitcoin can continue operating normally while wallets, node software, interfaces or third-party infrastructure suffer vulnerabilities that expose individual users to theft. Lightning adds another operational layer because users may manage hot funds, payment channels, remote interfaces and online nodes simultaneously. That can improve payment speed and usability but creates more components that must be secured correctly. For BTCPay operators, the immediate priority is updating to version 2.4.2, reviewing transaction and channel activity and rotating credentials for any independently exposed LND connection. Users running custom networking setups also need to verify that old routes are not still reachable after the update. The longer-term test will be how BTCPay restores remote connectivity without recreating the same attack path. Until then, restricting public access reduces convenience but removes a route attackers have already shown they can exploit to reach Lightning funds.