
BTCPay restricts remote LND access after attackers drained Lightning nodes via exposed macaroons; 2.4.2 rotates credentials, custom setups still exposed.
BTCPay Server has blocked public remote connections to Lightning nodes running Lightning Network Daemon, or LND, after attackers exploited a vulnerability that exposed the credentials controlling those nodes.
The project released version 2.4.2, which installs LND 0.21.1 and automatically regenerates those credentials, called macaroons, on standard BTCPay deployments. Rotating the files invalidates stolen copies once operators update.
The flaw let an unauthenticated remote attacker obtain macaroons, which grant access to LND functions, according to BTCPay. With those credentials, an attacker could take control of a node and transfer funds without the operator's authorization.
Two operators have publicly reported losses. Zach Herbert, CEO of hardware-wallet maker Foundation, said its Lightning node was drained overnight. He later said the hot wallet was not affected, while Lightning channels were closed and the funds swept. Bitcoin publication Citadel21 also said its Lightning node had been swept. Neither disclosed how much was taken.
The temporary restriction stops external wallets such as Zeus from connecting through a BTCPay Server domain or Tor onion address on Docker setups. BTCPay said Lightning payments can continue, so the measure targets remote administrative access rather than the payment layer itself.
The automatic credential rotation does not cover every configuration. Operators who exposed LND through their own reverse proxy, Tor service, forwarded port, or another access route outside BTCPay have to rotate credentials separately. Installing version 2.4.2 does not close remote connections that an administrator created independently of BTCPay's standard setup.
An operator might assume the update removed all exposure while separate networking rules remain active. BTCPay is asking users with custom deployments to review both their credentials and how the node is reachable from the internet.
The incident did not compromise Bitcoin's underlying network. The risk came from software and credentials used around Lightning infrastructure, separate from Bitcoin's consensus or transaction protocol.
The BTCPay problem follows a Coldcard hardware-wallet flaw that was linked to more than $100 million in confirmed losses. The events are unrelated, and both affected products surrounding Bitcoin rather than Bitcoin itself.
Lightning adds another set of moving parts because users may manage hot funds, payment channels, remote interfaces, and online nodes at the same time. That can speed up payments and improve usability. It also creates more components that must be secured.
For BTCPay operators, the immediate step is updating to 2.4.2 and rotating credentials for any independently exposed LND connection. Operators should also check for unauthorized payments, unexpected channel closures, unfamiliar peers, and balance mismatches between expected holdings and what appears onchain or through Lightning. Users with custom networking setups need to verify old routes are not still reachable after the update.
BTCPay has not said when public remote access will be restored. The restriction removes a route attackers have already shown they can exploit to reach Lightning funds.
Drafted by a large language model from the source reporting linked above, then screened by automated publishing checks. It is not read by a journalist before publication. Some articles cite our Alpha Score. Verify prices and figures against the original source. Educational coverage, not personalized advice.