BTCPay has urged users running LND to either update immediately or shut down their servers after attackers stole sensitive credentials capable of controlling Lightning wallets and moving funds.
What has already been a difficult week for Bitcoin software has taken another turn, this time affecting merchants who accept bitcoin payments through the Lightning Network — a layer built on top of Bitcoin for fast and low-cost transactions.
Late Friday, attackers targeted Lightning nodes connected to BTCPay Server, exploiting a critical vulnerability that exposed protected credentials, the team said in a post on X.
BTCPay confirmed that funds were stolen and advised all LND users — the most commonly used software for operating Lightning nodes — to upgrade to version 2.4.2 or take their servers offline as a precaution.
The project has not yet revealed how many users were impacted or the total amount of bitcoin lost.
The vulnerability allowed unauthenticated remote attackers to access “.macaroon” files, which act as permission credentials for interacting with an LND node. According to BTCPay, attackers specifically targeted these files, enabling them to gain control of nodes and transfer funds.
Among those affected was hardware wallet company Foundation. CEO Zach Herbert said the attackers emptied the firm’s BTCPay Lightning node overnight, closing channels and withdrawing funds, while its on-chain hot wallet remained unaffected.
Bitcoin publication Citadel21, run by pseudonymous figure hodlonaut, also reported that its Lightning node had been drained, though it noted only a small amount of funds were held there.
The vulnerability had previously been reported to BTCPay by members of the Bitcoin Red Team — a group of developers using AI tools to scan bitcoin codebases. The team has already flagged thousands of issues across hundreds of projects.
BTCPay credited Red Team contributors Craig Raw, Rob Hamilton, Calle, and Evan Kaloudis for responsibly disclosing the flaw and assisting with its analysis.
The group said it chose to release findings quickly because others were likely to discover the same vulnerabilities. By the time BTCPay issued its public warning, attackers were already exploiting the flaw on live systems.
Following its initial alert, BTCPay clarified that its standard on-chain wallets, including hot wallets created within the platform, are not affected by this issue.
The vulnerability specifically impacts setups using LND. However, funds stored in LND’s own on-chain wallet may still be at risk, as they are tied to the compromised Lightning node.
BTCPay has not yet shared full technical details of the flaw, stating that operators need time to secure their systems. A detailed postmortem is expected in the coming days.

More Stories
Why T. Rowe Price Added Memecoins to Its New Crypto ETF
Senate Advances Crypto Clarity Act With First Vote Ahead of September Push
U.S. Expands Iran Crypto Sanctions, Targets Two Exchanges