BTCPay Server patches critical flaw that let attackers hijack Lightning nodes

BTCPay Server is offering a recovery bounty worth 10% of any returned funds, capped at 3 BTC, after attackers exploited a critical flaw in versions before 2.4.2 to steal LND admin macaroon credentials and drain connected Lightning wallets, while leaving Bitcoin itself and BTCPay's on-chain wallets unaffected. The open-source Bitcoin payments project said the offer is open to anyone who provides useful information, including the attacker, with payouts split if multiple tips contribute to a recovery, while warning operators that patching alone is insufficient because compromised Lightning credentials must also be rotated. Foundation Devices and Citadel21 have disclosed losses, though BTCPay has not published the total amount stolen, and the project urged merchants to keep most funds in cold storage and move excess balances out of hot wallets regularly during what it described as a period of rapid, AI-driven change. The project separately paid 0.21 BTC each to Craig Raw and the Bitcoin Red Team Fund for the private disclosure that led to the patch, and said exchanges, blockchain analytics firms and law enforcement are helping trace the funds.

The information on this website is generated using AI and we cannot guarantee its accuracy. Please use it as reference information only.