BTCPay urges immediate LND updates after stolen credentials threaten Lightning funds

BTCPay warned users running LND to update to version 2.4.2 immediately or take servers offline after attackers exploited a critical BTCPay Server vulnerability and stole funds from Lightning nodes. The flaw let unauthenticated remote attackers obtain LND ".macaroon" credential files, which can be used to control a node, close channels and move funds. BTCPay said the issue affects deployments using LND rather than its standard on-chain wallets, including hot wallets generated inside BTCPay, though funds in LND's own on-chain wallet can still be at risk because they sit under the compromised Lightning node. Foundation and Citadel21 said their Lightning nodes were swept. BTCPay and the Bitcoin Red Team are investigating and plan to publish a fuller postmortem in the coming days.

本网站上的信息是使用AI生成的,我们无法保证其准确性。 请仅作为参考信息使用。