AltcoinBuzzAltcoinBuzz
Subscribe
  • Crypto News
  • Crypto Research
  • Technical Analysis
AltcoinBuzzAltcoinBuzz

An independent digital media outlet delivering crypto research, news, and technical analysis to a community of 600,000+ users.

Follow us on:

Discover

  • Crypto Research
  • Crypto News
  • Technical Analysis
  • Key Opinions
  • Upcoming Launches

Categories

  • Bitcoin BTC
  • RWA
  • Technology
  • Altcoins
  • Regulation

Company

  • Affiliates
  • Partners & Sponsors
  • Careers
  • Contact
  • Terms of Use
  • Subscription Terms
  • About the ALTCOINBUZZ
  • Privacy Policy
  • Contact ALTCOINBUZZ
  • Advertise with us

Copyright 2026 ALTCOINBUZZ. All rights reserved.Something is buzzzzzzzing.
HomeCrypto ResearchBTCPay Server restricts Lightning access after attackers steal funds
Crypto ResearchTechnologyBitcoin BTC

BTCPay Server restricts Lightning access after attackers steal funds

BTCPay Server has restricted remote Lightning access after attackers exploited a critical vulnerability and drained funds from at least two Lightning nodes.

BBikash Deka•Aug 9, 2026
BTCPay Server restricts Lightning Network access after security attack
MentionedBTC$65,181.00+0.40%

BTCPay Server has temporarily restricted public remote access to Lightning Network nodes running LND after attackers exploited a critical vulnerability and used stolen credentials to move funds.

The open-source Bitcoin payment processor said the restriction affects external wallets such as Zeus when they connect through a BTCPay Server domain or Tor onion address on Docker-based installations.

BTCPay said normal Lightning payments can continue. The project plans to restore remote access once it determines that the connection method is safe.

The incident adds to a growing list of recent security problems affecting software and services built around Bitcoin.

Earlier, we reported on a separate BTCPay Server exploit alongside a Trezor phishing attack, which showed how vulnerabilities outside the Bitcoin network itself can still put user’s funds at risk.

BTCPay Server Blocks Remote Lightning Connections

The latest security response focuses on public remote connections to LND nodes.

BTCPay said attackers were able to access sensitive macaroon credentials, which are authentication files used to control an LND node. Once obtained, these credentials could allow an attacker to control the node and move its funds.

As a result, BTCPay has temporarily blocked external connections through BTCPay Server domains and Tor addresses on affected Docker deployments.

Users can still process Lightning payments, but certain remote-wallet connections are temporarily unavailable.

The project said the restriction will remain until the team is confident that remote access can be safely restored.

BTCPay 2.4.2 Updates LND and Rotates Credentials

BTCPay Server recommends upgrading to version 2.4.2.

The update includes LND version 0.21.1 and automatically regenerates macaroon credentials on standard BTCPay installations.

This credential rotation is important because simply updating the software may not be enough if an attacker already obtained the old credentials.

After updating, operators should check their nodes for signs of unauthorized activity.

BTCPay recommends looking for:

  • Unauthorized Lightning payments
  • Unexpected channel closures
  • Unknown or unfamiliar peers
  • Changes in on-chain balances
  • Differences between recorded and actual Lightning balances

These checks can help operators determine whether their nodes were accessed before the security update was installed.

Some Operators Must Rotate Credentials Manually

The update does not automatically protect every possible BTCPay configuration.

Operators who expose their LND nodes through an independent reverse proxy, Tor service, forwarded port, or another external connection method must rotate their credentials separately.

BTCPay warned that installing version 2.4.2 does not automatically close access routes managed outside the standard BTCPay setup.

This means operators need to review their own infrastructure and make sure that previously exposed credentials can no longer be used.

At Least Two Lightning Nodes Reported Losses

The exact scale of the attack is still unclear.

At least two operators have publicly reported that their Lightning nodes were drained.

Foundation CEO Zach Herbert said the hardware-wallet company's Lightning node was drained overnight. He later clarified that the company's hot wallet was not affected.

Instead, the attackers closed Lightning channels and swept the funds held through those channels.

Bitcoin publication Citadel21 also reported that its Lightning node had been drained.

Neither organization publicly disclosed how much Bitcoin was lost.

As a result, the total amount stolen and the number of affected BTCPay operators remain unknown.

How the BTCPay Vulnerability Put Funds at Risk

The attack centered on the credentials used to control LND nodes.

Macaroons act as authentication credentials for Lightning applications. If an attacker obtains credentials with sufficient permissions, they may be able to perform actions on the node without needing the operator's normal login process.

In this case, BTCPay said an unauthenticated remote attacker could obtain macaroon files.

That created a direct path from a software vulnerability to the funds held by affected Lightning nodes.

The incident highlights an important distinction: the Bitcoin blockchain itself was not compromised.

Instead, the attack targeted software and infrastructure used to operate Lightning payments.

BTCPay Attack Follows Recent Bitcoin Security Incidents

The BTCPay incident comes shortly after several other security events affecting Bitcoin-related products.

A recent Coldcard vulnerability has been linked to more than $100 million in confirmed Bitcoin theft, while the separate Trezor phishing campaign showed how attackers can steal funds by tricking users into revealing their recovery seeds.

These incidents have different causes, but they share an important lesson.

Bitcoin's underlying network can remain secure while applications, wallets, servers and user behavior around it create opportunities for attackers.

That makes software updates, credential management and secure infrastructure especially important for users operating Lightning nodes.

What BTCPay Operators Should Do Now

BTCPay Server operators should treat the incident seriously, particularly if they run LND.

The first step is to upgrade to BTCPay Server 2.4.2 and make sure LND is updated to version 0.21.1.

Operators should then:

  1. Check their Lightning and on-chain balances.
  2. Review recent payments and channel closures.
  3. Look for unfamiliar Lightning peers.
  4. Rotate credentials if they use custom access routes.
  5. Check reverse proxies, Tor services and forwarded ports.
  6. Move funds if they find evidence of unauthorized access.
  7. Review their server configuration for unnecessary public exposure.

Operators should also avoid assuming that an upgrade alone means their node is safe if they previously exposed LND through an independently managed connection.

Bitcoin Lightning Security Remains a Key Concern

The BTCPay Server attack shows how quickly a vulnerability in supporting infrastructure can become a financial risk.

At this stage, the full impact of the incident is still unknown. However, the reports from Foundation and Citadel21 confirm that attackers were able to move funds from at least some affected Lightning nodes.

For operators, the priority is to update BTCPay Server, rotate exposed credentials and carefully review node activity.

The Bitcoin network itself has not been compromised. The incident instead highlights the security risks that can exist in the software and infrastructure built around Bitcoin and the Lightning Network.

The information discussed by Altcoin Buzz is not financial advice. This is for educational, entertainment, and informational purposes only. Any information or strategies are thoughts and opinions relevant to the accepted levels of risk tolerance of the writer/reviewers and their risk tolerance may be different than yours. We are not responsible for any losses that you may incur as a result of any investments directly or indirectly related to the information provided. Bitcoin and other cryptocurrencies are high-risk investments so please do your due diligence. This post is sponsored by Market Across.

Copyright Altcoin Buzz Pte Ltd.

Related

BIP-110 Bitcoin fork stops after producing only two blocks
TechnologyBitcoin BTC
Aug 9, 2026

BIP-110 Bitcoin fork mines two blocks, then stops

The controversial BIP-110 Bitcoin fork has produced only two blocks after splitting from the main chain. With very little mining power supporting it, the breakaway chain now faces long block times and potential replay-attack risks.

BTC
Saloni Rathi
Trezor phishing scam
Bitcoin BTCTechnology
Aug 8, 2026

Trezor phishing ad and BTCPay exploit put Bitcoin users at risk

A fake Trezor ad reportedly drained about $1.6 million in Bitcoin, while BTCPay Server patched a critical flaw under active exploitation.

BTC
Bikash Deka
Bitcoin BIP-110 fork replay attack showing how fork coin transactions could affect real BTC
TechnologyBitcoin BTC
Aug 8, 2026

Bitcoin holders could lose real BTC in a BIP-110 fork replay attack

Bitcoin holders could lose real BTC if they sell coins from a BIP-110 fork before replay protection is active. Developers urge caution if the chain splits.

BTC
Bikash Deka
Zach Herbert 🇺🇸
Zach Herbert 🇺🇸
FOUNDATION
@zherbert
·Follow

How many BTCPay lightning nodes were swept? Our Foundation node was drained overnight by attackers.

BTCPay Server
BTCPay Server
@BtcpayServer

There is a critical vulnerability being actively exploited on BTCPay Server, which can result in the loss of funds. Please update your BTCPayServer to 2.4.2 by going to Admin Dashboard -> Server -> Maintenance -> Update & verify the 2.4.2 version string in the footer. If you

6:01 PM · Aug 7, 2026
640
Reply
Read 72 replies
hodlonaut #BIP-110
hodlonaut #BIP-110
@hodlonaut
·Follow

This is an ongoing attack on BTCPayserver users. Citadel21's lightning node was just swept. Fortunately there were not much funds there, due to cautionary steps before BIP-110 activation. Praying for all other affected users.

Image
BTCPay Server
BTCPay Server
@BtcpayServer

There is a critical vulnerability being actively exploited on BTCPay Server, which can result in the loss of funds. Please update your BTCPayServer to 2.4.2 by going to Admin Dashboard -> Server -> Maintenance -> Update & verify the 2.4.2 version string in the footer. If you

5:44 PM · Aug 7, 2026
331
Reply
Read 20 replies