BTCPay Server flaw exposed Lightning node credentials, letting attackers steal funds

A serious vulnerability in BTCPay Server exposed credentials for connected Lightning nodes running LND, allowing attackers to seize control of those nodes and drain funds. Victims included Foundation, the hardware-wallet maker, and a bitcoin publication. The breach highlights a recurring risk in Bitcoin payments infrastructure: when merchant software is tightly linked to Lightning operations, a compromise in the payment layer can expose the credentials needed to move funds.

The information on this website is generated using AI and we cannot guarantee its accuracy. Please use it as reference information only.