Skip to content
Bitcoin

Another Bitcoin Infra Exploit Hits BTCPay Server, Draining Merchant Lightning Nodes

Tether coin surrounded by security, banking, dollar, and verification icons.

Another major exploit has shaken the Bitcoin ecosystem, this time targeting merchants who use BTCPay Server to handle Lightning Network payments. According to a CoinDesk report, attackers leveraged a critical vulnerability in BTCPay Server to drain funds from Lightning nodes running LND (Lightning Network Daemon), prompting urgent calls for users to update or shut down immediately.

How the BTCPay Exploit Worked

The flaw allowed unauthenticated attackers to access LND “.macaroon” credential files stored by the BTCPay Server. With these credentials, they could seize control of the Lightning node and sweep all funds from open channels. The incident adds to a troubling trend; previously, Bitcoin Cold Wallets Drain $70M in Attack That Never Touched Hardware, Galaxy Research Reveals highlighted how even cold storage setups aren’t immune to sophisticated exploits.

Hardware-wallet maker Foundation and Bitcoin publication Citadel21 were among the confirmed victims, with their Lightning nodes entirely drained. The urgency echoes the recent Coinkite CEO Tells Coldcard Users to ‘Move Your Funds Now’ Amid Security Alert, BOJ Keeps Rate warning, underlining that even well-known infrastructure providers can be caught off guard.

BTCPay’s on-chain wallets were not impacted, the team confirmed, because they rely on a different security model. However, any Lightning node behind a vulnerable BTCPay instance was at risk. This is reminiscent of the Coldcard Firmware Bug Drains 594 BTC in 25 Minutes, $38 Million Stolen incident, where a similar low-level bug led to massive losses, underscoring the persistent software risks across Bitcoin infrastructure.

Response and What This Means for Bitcoin Merchants

BTCPay developers quickly released version 2.4.2 to patch the vulnerability and urged all server operators running LND to update immediately or take their nodes offline to prevent further thefts. The Bitcoin Red Team is investigating and a full postmortem is promised. The incident raises fresh questions about the maturity of Lightning Network infrastructure for merchant adoption, even as Bitcoin’s base layer remains secure.

BTC-Pulse

Related stories

More coverage from this topic.