Live Markets:
BTC Loading...
ETH Loading...
SOL Loading...
XRP Loading...
ADA Loading...
LTC Loading...
Cryptorah
Breaking
Zeus Wallet Shuts Down Infrastructure After Cybersecurity Breach, Customer Funds Secure ZeroStack Flags Going-Concern Doubt After 0G Holdings Lose 91% of Their Cost Basis XRP Faces Critical Channel Breakout Test as Korean Buyers Outnumber Sellers 2-to-1 White House Teleprompter Operator Exits After $100K+ Prediction Market Scandal Washington Moves to Cut Chinese Optical Transceivers Out of AI Data Centers Trump Media Walks Away From $6.4B Crypto.com CRO Plan as Token Hits Three-Year Low Trump Media Dumps $165M in Bitcoin as Coldcard Losses Hit $88M and FTX Pushes $900M to Creditors Trump Cancels Iran Strikes, Jobs Data Looms: Can Crypto Break Out This Week? Thune Files Cloture on CLARITY Act, Setting Up September Showdown Over Crypto Rules Telegram now faces legal fire on three fronts at once, as Australia sues over terror content Stolen Coldcard Bitcoin Moves for the First Time — $1.94M Transfer Reignites Cash-Out Watch Step App Shuts Down: Move-to-Earn Platform Ends Four-Year Run as FITFI Craters Stablecoins Offer No Systematic Edge Over Traditional Remittances, Bank of Italy Study Finds South Korea Weighs Interim Stablecoin Rules to Bridge the Gap Before Its Crypto Law Lands South Korea Moves Toward Unified Crypto Framework as Tax Repeal Debate Intensifies Senate Shelves Crypto Clarity Act as Russian Sanctions and Limited Floor Time Squeeze Industry's Regulatory Hopes Saylor's Warning: Bitcoin's Constitution Is Under Threat From Inside, Not Outside Russia Expands Cryptocurrency Mining Ban to Capital Region Through 2032 Pump.fun Layoffs Two Months Before Multi-Million Dollar Token Vesting Spark Controversy Pi Network Token Surges 15% as Bitcoin Tests $65K Resistance Onyx Security Lands $113M Series B to Police Autonomous AI Agents Inside the Enterprise New York Launches Legal Battle Against Kalshi, Alleging Illegal Gambling Operation Korean Police Crack Down on $8.6M XRP Staking Scam as Token Holds Ground Italy's Largest Bank Triples Staked Ether ETF Position While Slashing Bitcoin IBIT Holdings Iran-Oman Talks Show Progress on Strait of Hormuz as Bitcoin Rallies Above $65K Hyperliquid's RWA Trading Surges to One-Third of Total Volume as Tokenized Assets Reshape DEX Activity Hungary Scraps Crypto Validator Rule as CoinCash Secures First MiCA License Grayscale CEO Files to Sell Entire Pre-Conversion XRP Trust Stake as Fund Shrinks 51% Google Reshuffles AI Leadership: Hassabis Moves to Chairman Role as DeepMind Loses CEO Position Frontier AI Is Splitting Crypto Security Into Haves and Have-Nots Four Augusts in the Red: Can XRP Finally Break Its Bearish Summer Streak? Former LAPD Officer Sentenced to Life for Armed Bitcoin Robbery Disguised as Police Raid Fed's Hawkish Hold Rattles Crypto: Bitcoin Defends $64K as Liquidations Top $300M EthSystems Launches Privacy Layer to Bridge Traditional Finance and Public Blockchains Ethereum MEV-Bot Hacker Turns $7.7M Heist Into a $505K Trading Loss ELIZAOS Token Officially Abandoned: Founder Walks Away After Lawsuit Drains Treasury Crypto Industry Leaders Dismantle WSJ Editorial Line-by-Line as CLARITY Act Debate Intensifies Crypto Industry Doubles Down on Michigan House Race with $2M Campaign Blitz Crypto Exchanges Go TradFi: Tokenized Stocks and Commodities Hit $6.6 Billion Crypto Braces for a Four-Catalyst Week: Iran Truce, CLARITY Act Vote, Fed Decision, PCE Data Critical Vulnerability in Coldcard Hardware Wallets: 594 BTC Stolen After Years-Long Entropy Flaw Court clears Bybit to chase the money trail behind its $1.5B North Korea hack Coldcard's Weak-Seed Bug Claims a Fourth Wave — Nearly 449 BTC Moved in Hours Coldcard's Five-Year Randomness Bug: Why Auditors Missed a Silent Swap in the Wallet's Core Security Function Coldcard Wallet Breach: Confirmed Bitcoin Losses Cross $100M, Fourth Attack Wave Under Investigation Coldcard Firmware Attack Drains $70M in Bitcoin as Fear Index Hits All-Time High Coinbase Secures Full UK Investment License, Launches Tokenized US Stocks With Dividend Rights Coinbase Canada Pushes for Regulatory Clarity as It Eyes Derivatives and Tokenized Asset Expansion Claude AI Projects $150K Bitcoin by December 2026 as Supply Squeeze Tightens CLARITY Act Gets Its Senate Vote — Just Not Necessarily the 60 It Needs China Accelerates Gold Reserves with Largest Monthly Purchase in Three Years CFTC Warns Prediction Market Platforms Against Generic Event Contract Filings BTCPay Server Blocks Remote Lightning Access After Credential-Theft Attack Drains Nodes Brazil Imposes 24-Hour Crypto Transfer Holds to Combat Cross-Border Fraud BlackRock Expands Tokenized Money Market Funds to Europe via JPMorgan Kinexys BlackRock Cuts iShares Ethereum ETF Trading Costs by 71% Through Reverse Split BlackRock and 140+ Institutions Launch Ethereum-Based Stablecoin as ETF Inflows Hit $11.2 Billion BitMart Shuts Down After 9 Years, BMX Token Crashes 58% Bitget to wind down Japan operations, force-close open positions by year-end Bitget Signs Agreement to Pursue Licensed Crypto Operation in Bhutan's Gelephu Zone Bitcoin's Price/Capital-Flow Split Echoes the Signal That Called the Last Cycle Bottom Bitcoin Tests Critical $68,500 Resistance Wall as Fed Decision Looms Bitcoin Steadies Under $64K Post-FOMC as Pi Network Rallies and Talus (US) Storms the Top 100 Bitcoin Stalls at $63K While BEAT and MemeCore Post Double-Digit Weekend Gains Bitcoin On-Chain Activity Hits 8-Month High as Coldcard Users Race to Migrate Wallets Bitcoin Grinds Back Above $63K After a Whiplash Week — But Audiera (BEAT) Keeps Bleeding Bitcoin Faces Four Converging Headwinds as Price Tests $62K Support Bitcoin Drops Below $64K as Korean Markets Crater and U.S. Crypto Bill Stalls Bitcoin and Gold Are Both Down Big — the "Quiet Accumulation" Story Behind Both Isn't as Clean as It Sounds Binance Wallet's $50,000 NES Perpetuals Competition: How Privacy-Focused AI Traders Can Compete Binance Adds Gold and Silver Options to Its Abu Dhabi-Regulated Exchange Bhutan's Bitcoin Sell-Off Continues: Another 435 BTC Hits Binance Bhutan Appoints 3iQ as First Institutional Manager for Bitcoin Treasury in Historic Sovereign Crypto Mandate BEAT Token Rockets 50% While Bitcoin Struggles Below $65K in Weekend Trading Antora Energy Secures $550M to Scale Thermal Battery Manufacturing for AI Infrastructure and Industrial Heat Analyst Says Bitcoin's Cup-and-Handle Just Broke Out — With a $220K Minimum Target Amsterdam Startup Bets $43M That Rust Can Outlast Lithium on Europe's Grid Aave Governance Weighs Pruning Six Blockchains and 50 Idle Markets in Risk-Framework Cleanup $3.6B EverSource Wealth Advisors Discloses XRP and Bitcoin ETF Holdings in Latest SEC Filing $10.4 Billion in Crypto Options Expire Today — Here's What the Positioning Says 10 Best Crypto Tax Software Tools 2026 - Complete Review & Comparison
Sponsored Advertisement Sponsored Ad
news

BTCPay Server Blocks Remote Lightning Access After Credential-Theft Attack Drains Nodes

Foundation and Citadel21 report swept Lightning channels as BTCPay restricts external wallet connections through Docker deployments following LND vulnerability exploit.

Jane Doe

By Jane Doe

Published on Aug 9, 2026

8 min read
Make Cryptorah Icon Cryptorah preferred on Google
BTCPay Server Blocks Remote Lightning Access After Credential-Theft Attack Drains Nodes

Quick Take

  • BTCPay Server temporarily disabled public remote connections to Lightning nodes running LND after attackers stole macaroon credentials and moved funds
  • Version 2.4.2 automatically installs LND 0.21.1 and regenerates credentials; operators advised to check for unauthorized payments and channel closures
  • Foundation and Citadel21 confirmed drained Lightning nodes, but total losses and number of affected operators remain unknown
  • The breach marks the latest security incident in widely-used Bitcoin infrastructure, following the Coldcard hardware wallet flaw linked to over $100 million in losses

What Happened

BTCPay Server, an open-source Bitcoin payment processor, has temporarily restricted public remote connections to Lightning Network nodes after attackers exploited a critical vulnerability in Lightning Network Daemon (LND) software to steal credentials and drain funds from multiple operators.

The vulnerability allowed unauthenticated remote attackers to obtain "macaroon" credential files—the authentication tokens that control LND node operations. With these stolen credentials, attackers gained complete control over Lightning nodes and moved funds without authorization.

The restriction specifically blocks external wallet applications such as Zeus from connecting through a BTCPay Server domain or Tor onion address on Docker deployments. BTCPay emphasized that Lightning payments can continue to function despite the restriction, and the team plans to restore remote-access functionality once they determine it is safe to do so.

At least two prominent operators have publicly confirmed losses. Foundation, a Bitcoin hardware wallet company, reported that its Lightning node was drained overnight. CEO Zach Herbert later clarified that while the company's hot wallet remained unaffected, all Lightning channels were forcibly closed and the funds swept by attackers. Bitcoin publication Citadel21 also disclosed that its Lightning node had been completely swept.

Neither organization has disclosed the specific amounts stolen, and the total scope of the attack—including the number of affected operators and aggregate losses—remains unknown at this time.

Why It Matters

Infrastructure Security Risk: This incident exposes critical vulnerabilities in widely-deployed Bitcoin infrastructure components, not the Bitcoin protocol itself. BTCPay Server is used by thousands of merchants and operators worldwide for Bitcoin and Lightning payments, making this a significant security event for the broader Bitcoin ecosystem.

The breach represents the latest in a concerning series of security incidents affecting Bitcoin-adjacent software and hardware. It follows closely on the heels of the Coldcard hardware wallet vulnerability, which has been linked to confirmed losses exceeding $100 million. Importantly, both incidents affected software and hardware surrounding Bitcoin rather than the network's underlying protocol—a distinction that underscores the layered nature of Bitcoin security.

For Lightning Network operators, the attack demonstrates that remote access convenience comes with substantial security trade-offs. The ability to manage Lightning nodes remotely through mobile wallets like Zeus has been a key usability feature, but this incident reveals how credential exposure can lead to complete node compromise.

The speed at which operators reported drained nodes—Foundation noted overnight drainage—suggests attackers moved quickly once they obtained credentials, leaving little time for detection or response. This highlights the need for proactive monitoring systems and security best practices among Lightning operators.

The Numbers

2.4.2 BTCPay Server patch version
0.21.1 Updated LND version
2+ Confirmed affected operators
$100M+ Coldcard-related losses (separate incident)

⚠️ Unverified: The total amount stolen in the BTCPay/LND attack and the complete number of affected operators have not been disclosed. Only Foundation and Citadel21 have publicly confirmed losses, with neither organization revealing specific dollar amounts.

Technical Details: The Vulnerability

The vulnerability centered on the exposure of macaroon credential files used by LND to authenticate and authorize operations. Macaroons function as bearer tokens in the Lightning Network—possession of a valid macaroon grants the holder the ability to perform actions on an LND node without further authentication.

According to BTCPay's security advisory, the flaw allowed remote attackers to access these credential files without any prior authentication. Once obtained, the macaroons provided attackers with the capability to:

  • Issue unauthorized Lightning payments
  • Force channel closures
  • Connect to unfamiliar peers
  • Move both Lightning and on-chain funds controlled by the node

The attack vector specifically affected BTCPay Server Docker deployments where LND was exposed through BTCPay's domain or Tor infrastructure. Operators who exposed LND through their own reverse proxy, custom Tor service, forwarded port, or other independent routing mechanisms face additional risk, as the automatic credential rotation in version 2.4.2 does not close access routes managed outside BTCPay's control.

Technical Background: What are Macaroons?

Macaroons are authorization credentials used in LND that work similarly to cookies or API keys but with added flexibility. Unlike traditional bearer tokens, macaroons can be attenuated (restricted) to limit what actions they authorize. In this attack, however, attackers appear to have obtained admin-level macaroons with full node control permissions.

LND uses several types of macaroons with different permission levels: admin.macaroon (full control), invoice.macaroon (invoice operations), readonly.macaroon (query only), and others. The ability to steal admin macaroons represents a complete compromise of node security.

BTCPay's Response and User Actions

Automatic Security Update

BTCPay Server version 2.4.2 includes several critical security measures:

  • Automatic installation of LND version 0.21.1, which presumably patches the underlying vulnerability
  • Automatic regeneration of macaroon credentials on standard BTCPay installations, invalidating any previously stolen credentials
  • Temporary blocking of remote access through BTCPay domains and Tor addresses to prevent further exploitation

Recommended Operator Actions

BTCPay has advised all operators running Lightning nodes to immediately:

  1. Update to version 2.4.2 to install the patched LND version and trigger credential rotation
  2. Review transaction history for any unauthorized payments or suspicious activity
  3. Check for unexpected channel closures that may indicate attacker activity
  4. Audit peer connections to identify unfamiliar nodes that shouldn't be connected
  5. Verify balances across both on-chain and Lightning Network channels to identify any discrepancies

Important: Operators who expose LND through their own reverse proxy, Tor service, forwarded port, or any route outside BTCPay's management must manually rotate their credentials. The automatic update only secures access routes managed directly by BTCPay Server.

What's Next

BTCPay Server plans to restore remote access functionality for external wallets once the team determines it is safe to do so. The timeline for this restoration has not been specified and will likely depend on thorough security audits and confirmation that the vulnerability has been fully addressed across the Lightning Network ecosystem.

Operators should watch for:

  • Official announcements from BTCPay regarding when remote access will be safely restored
  • Disclosure of attack scope including total losses and number of affected nodes, if this information becomes available
  • Post-mortem analysis detailing how the vulnerability was discovered and exploited
  • LND security updates from Lightning Labs regarding any additional recommended actions
  • Industry-wide security reviews of other Lightning implementations and BTCPay alternatives

Given the pattern of recent high-profile security incidents in Bitcoin infrastructure—particularly the Coldcard vulnerability mentioned alongside this breach—the broader Bitcoin development community may initiate more comprehensive security audits of widely-deployed tools and hardware.

Context: July 2026 Security Landscape

The BTCPay/LND incident occurred in the context of what has been reported as the second-worst month for cryptocurrency losses in 2026. According to information referenced in the source material, July 2026 saw losses reach $247 million, with the Coldcard hardware wallet exploit contributing to a significant portion of that total. This concentration of high-impact vulnerabilities in trusted infrastructure has raised concerns about the security posture of the broader Bitcoin ecosystem.

Frequently Asked Questions

Is the Bitcoin network itself affected by this vulnerability?

No. This vulnerability affected BTCPay Server software and the Lightning Network Daemon (LND) implementation—tools that interact with Bitcoin—not the Bitcoin protocol itself. The underlying Bitcoin network continues to operate normally and securely.

Can I still accept Lightning payments if I use BTCPay Server?

Yes. BTCPay Server explicitly stated that Lightning payments can continue to function. The restriction only affects remote access through external wallet applications like Zeus; the core payment processing capability remains operational.

How do I know if my Lightning node was compromised?

Check your node for: (1) unauthorized outgoing payments you didn't initiate, (2) channels that were closed without your action, (3) unfamiliar peer connections you didn't establish, and (4) discrepancies between your recorded balances and actual on-chain or Lightning balances. If you find any of these signs, update immediately to version 2.4.2 and consider your previous credentials compromised.

What are macaroon credentials and why are they important?

Macaroons are authentication tokens used by LND to control access to node operations. They function as bearer credentials—anyone possessing a valid macaroon can perform authorized actions on the node. Admin-level macaroons grant complete control, which is why their theft allowed attackers to drain funds entirely.

Will updating to version 2.4.2 protect me if I exposed LND through my own custom setup?

Not automatically. If you exposed LND through your own reverse proxy, Tor service, forwarded port, or other infrastructure outside BTCPay's management, you must manually rotate your macaroon credentials. The automatic credential rotation in version 2.4.2 only secures routes managed directly by BTCPay Server.

Investment disclaimer: The content reflects the author’s personal views and current market conditions. Please conduct your own research before investing in cryptocurrencies, as neither the author nor the publication is responsible for any financial losses.

Ad Disclosure: This site may feature sponsored content and affiliate links. All advertisements are clearly labeled, and ad partners have no influence over our editorial content.

Sponsored Advertisement Sponsored Ad
Jane Doe

About Jane Doe

Jane Doe is a senior blockchain journalist covering DeFi, Bitcoin, and web3 innovations since 2018.