BTCPay Server cut off the remote access path used by merchants connecting to Lightning nodes on separate hardware after attackers exploited a critical flaw affecting LND setups and drained funds from some operators. The project confirmed active exploitation and told users to upgrade to BTCPay Server 2.4.2 and LND 0.21.1, which rotates macaroon credentials on standard deployments, while merchants managing their own remote links through reverse proxies, Tor services or forwarded ports must review channel activity, verify balances and rotate access separately. Default same-server BTCPay deployments and standard on-chain wallets were not affected by the targeted remote-node path, though funds controlled by a compromised LND node remain at risk. The breach unfolded as a volunteer group of Bitcoin developers said an AI-assisted security sweep had identified about 5,000 vulnerabilities across nearly 400 open-source Bitcoin projects in 24 hours, including 85 critical and 635 high-severity bugs, heightening concern after the separate Coldcard exploit that drained almost 2,000 bitcoin worth just over $100 million from more than 5,200 addresses.