Monday, August 10, 2026
banner

The flaw exposed LND credential files in every version before 2.4.2, and at least two operators say their Lightning channels were emptied before the public warning went out.

Bitcoin Lightning Nodes Drained as Attackers Exploit BTCPay Vulnerability

Posted August 10, 2026 at 7:03 am EST.

BTCPay Server, the free, open-source, self-hosted bitcoin payment processor, said attackers exploited a critical vulnerability present in every version before 2.4.2 and stole user funds. The project urged anyone running its LND to update immediately.

The flaw let an unauthenticated remote attacker retrieve credential files, allowing them to take control of a node and move its funds.


This story is an excerpt from the Unchained Daily newsletter.

Subscribe here to get these updates in your email for free


Patching does not end the exposure, which is what makes this incident awkward for merchants. Credentials already stolen from a previously exposed server stay valid until they are rotated, so operators need to check their nodes for payments they did not make, unexpected channel closures and unfamiliar peers. BTCPay narrowed its guidance after the initial alert, confirming that its own on-chain wallets, including hot wallets, are not affected, though funds sitting in LND’s own on-chain wallet remain at risk because they belong to the compromised node.

At least two operators have gone public. Foundation, the maker of Passport hardware wallets, said its BTCPay Lightning node was drained overnight, with channels closed and funds swept, while its on-chain hot wallet was untouched, according to chief executive Zach Herbert. Citadel21, the bitcoin publication run by pseudonymous commentator hodlonaut, said its node was swept as well but held little.

BTCPay credited members of the Bitcoin Red Team, a group of developers that began aiming AI models at bitcoin codebases last week and has since filed thousands of findings across hundreds of projects, with disclosing the issue and helping analyze it. The incident lands days after a Coldcard firmware flaw tied to more than $100 million in confirmed losses.

Related Listen: Inside the Coldcard Hack That Drained Over $100 Million in Bitcoin: Uneasy Money

AI-assisted content: This article was produced with the assistance of AI tools and was reviewed, edited, and fact-checked by a member of the Unchained editorial team before publication.

Tech,BTCPay Server,Lightning Network,security,yahooBTCPay Server,Lightning Network,security,yahoo#Bitcoin #Lightning #Nodes #Drained #Attackers #Exploit #BTCPay #Vulnerability1786361862

banner
crypto & nft lover

Johnathan DoeCoin

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Ut elit tellus, luctus nec ullamcorper mattis, pulvinar.

Follow Me

Top Selling Multipurpose WP Theme

Newsletter

banner
crypto & nft lover

Johnathan DoeCoin

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Ut elit tellus, luctus nec ullamcorper mattis, pulvinar.

@2022 u2013 All Right Reserved. Designed and Developed by PenciDesign