BTCPay restricts remote Lightning access after attackers steal funds
BTCPay Server has temporarily restricted public remote connections to Lightning Network nodes running LND software after an exploit allowed attackers to steal funds by obtaining credentials. An update has been released to address the vulnerability and regenerate macaroon …
Intelligence analysis by Gemini 2.5 Flash

BTCPay Server has temporarily disabled public remote connections for LND-based Lightning nodes following a security breach where attackers exploited a vulnerability to gain control of nodes and steal funds. While an update is available to fix the issue and rotate credentials, the total impact and number of affected users remain unclear, with at least two operators publicly reporting l…
Imagine a special digital lock on your online money box that lets you send money super fast. Someone found a secret way to copy the key to this lock without asking and took some money. Now, the company that helps you use this lock has temporarily changed all the locks and given everyone new keys to keep their money safe, but some people still need to change their keys themselves.
Analysis
BTCPay Server
BTCPay Server has taken immediate action by temporarily restricting public remote connections to Lightning Network nodes that utilize the Lightning Network Daemon (LND) software. This measure was implemented after attackers successfully exploited a critical vulnerability, enabling them to obtain sensitive credentials and subsequently move funds from affected nodes. The restriction is a preventative step designed to safeguard users from further compromise.
The temporary restriction means that external wallets, such as Zeus, are currently unable to connect through a BTCPay Server domain or a Tor onion address on Docker deployments. Despite this, BTCPay has confirmed that Lightning payments can continue to function without interruption. The project has also stated its intention to restore the remote-access option once it deems the environment sufficiently secure, indicating a commitment to both security and functionality.
Macaroon Credentials
The vulnerability specifically allowed an unauthenticated remote attacker to obtain "macaroon" credential files. These files are crucial as they are used to control LND nodes, meaning their compromise grants attackers the ability to take full control of a node and move its associated funds. This highlights a significant security flaw in the credential management process.
In response, BTCPay Server has released version 2.4.2, which installs LND version 0.21.1. A key feature of this update is its ability to automatically regenerate macaroon credentials on standard BTCPay installations, thereby neutralizing the exploited vulnerability. This automatic rotation is vital for quickly securing a large portion of the user base.
Operators are strongly advised to conduct thorough checks for any signs of unauthorized activity, including unexpected channel closures, unfamiliar peer connections, or discrepancies in their onchain or Lightning balances. Furthermore, BTCPay emphasized that operators who expose LND through their own reverse proxy, Tor service, forwarded port, or other independent routes must manually rotate their credentials, as the update does not cover these custom configurations.
Foundation and Citadel21
At least two prominent operators have publicly reported losses stemming from this exploit. Zach Herbert, CEO of Foundation, a hardware-wallet company, stated that their Lightning node was drained overnight. He later clarified that while their hot wallet remained unaffected, their Lightning channels were closed and the funds swept, indicating a targeted attack on their Lightning infrastructure.
Similarly, Bitcoin publication Citadel21 also reported that its Lightning node had been swept by attackers. Both Foundation and Citadel21 have not disclosed the specific amounts of funds lost, and the total number of affected operators and the aggregate amount stolen across the network remain unknown. This lack of full disclosure contributes to uncertainty regarding the overall impact of the breach.
This incident follows other recent security breaches involving widely used Bitcoin products, such as a Coldcard hardware-wallet flaw linked to over $100 million in confirmed losses. BTCPay Server clarified that these separate incidents affect software surrounding Bitcoin, rather than the underlying Bitcoin network protocol itself, distinguishing them from fundamental blockchain vulnerabilities.
Key points
- BTCPay Server restricted remote Lightning access due to an exploit.
- Attackers stole funds by obtaining "macaroon" credential files for LND nodes.
- Version 2.4.2 updates LND and automatically regenerates credentials for standard installations.
- Operators are advised to check for unauthorized transactions and balance discrepancies.
- Foundation and Citadel21 publicly reported drained Lightning nodes.
The swift action by BTCPay Server to restrict access and release an update demonstrates a proactive approach to security, which could help mitigate further losses and restore user confidence. The ability to regenerate credentials automatically for standard installations simplifies the recovery process for many operators.
The fact that attackers successfully stole funds and the total impact remains unknown suggests potential for more widespread losses or undiscovered vulnerabilities. Operators who manage their own access routes must manually rotate credentials, which could lead to delays or oversight, leaving some exposed.



