Key Points BTCPay Server has disabled external remote access to Lightning Network nodes following exploitation of a severe security vulnerability Hackers acquired “macaroon” authentication fi
Key Points
- BTCPay Server has disabled external remote access to Lightning Network nodes following exploitation of a severe security vulnerability
- Hackers acquired “macaroon” authentication files that control LND nodes, enabling unauthorized fund transfers
- An emergency patch in version 2.4.2 fixes the vulnerability and automatically refreshes credentials for default configurations
- Foundation’s CEO Zach Herbert verified that his organization’s Lightning node experienced a complete drainage
- Citadel21, a Bitcoin-focused publication, similarly confirmed its Lightning node was compromised, with both parties withholding specific loss figures
In response to a critical security breach that enabled fund theft from multiple operators, BTCPay Server has implemented a temporary suspension of public remote connections to Lightning Network nodes.
The security incident specifically targeted infrastructure running Lightning Network Daemon software. Threat actors leveraged the security weakness to access “macaroon” authentication files—specialized credentials that grant operational control over LND nodes. With these credentials in hand, malicious actors gained unrestricted ability to transfer funds.
This protective measure blocks external wallet applications such as Zeus from establishing connections via BTCPay Server domains or Tor onion addresses on Docker-based deployments. Despite this restriction, BTCPay confirmed that Lightning payment functionality remains operational, with plans to reinstate remote access capabilities once security conditions permit.
Patch Details and Functionality
BTCPay deployed version 2.4.2 as an emergency response to the security incident. This release implements LND version 0.21.1 and executes automatic macaroon credential regeneration for standard deployment configurations.
Node operators who have configured LND routing through custom reverse proxies, independent Tor services, or port forwarding arrangements outside BTCPay’s standard setup must manually rotate their authentication credentials. The patch does not automatically secure access pathways that operators have configured independently.
BTCPay has issued guidance for all node operators to conduct thorough security audits, including examination of payment histories for suspicious transactions, verification of channel closure activity, identification of unknown network peers, and reconciliation of balance records across both onchain and Lightning accounts.
Confirmed Attack Victims
Zach Herbert, CEO of Foundation, made a public statement confirming that his organization’s Lightning node suffered a complete drainage during overnight hours. He subsequently provided clarification that the company’s hot wallet infrastructure remained secure and unaffected. The attack methodology involved forced channel closures followed by systematic fund extraction.
Bitcoin-focused media outlet Citadel21 likewise confirmed becoming a victim of the attack, reporting that its Lightning node had been completely emptied. Both affected parties have declined to reveal the precise monetary value of their losses.
The complete scope of the breach, including the total count of compromised operators, has not been determined.
This security incident arrives on the heels of a distinct vulnerability discovered in Coldcard hardware wallets that resulted in documented losses exceeding $100 million. Both security breaches targeted Bitcoin ecosystem infrastructure and supporting software rather than compromising Bitcoin’s core protocol or blockchain network.
BTCPay has explicitly stated that these two security incidents bear no connection to one another. Nevertheless, the succession of infrastructure vulnerabilities has heightened security awareness and vigilance throughout the Bitcoin operator community.
BTCPay has committed to reactivating remote access features following comprehensive security verification, though no specific restoration timeline has been announced.
All operators running affected systems are strongly encouraged to deploy the security update without delay and conduct comprehensive reviews of node activity to identify potential indicators of unauthorized access or compromise.
The post BTCPay Server Suspends Lightning Node Remote Access Following Security Breach appeared first on Blockonomi.