TechNew Exploit Targets Bitcoin's Lightning Network, Compromising Payment Servers

BTCPay has alerted users operating LND to update their systems immediately or take their servers offline following a breach that allowed attackers to access Lightning wallets.

By Shaurya MalwaUpdated 12 min agoPublished 14 min ago2 min readMake preferred on ShareShare this articleCopy linkX (Twitter)LinkedInFacebookEmailMake preferred on New exploit affects Lightning payment servers, impacting merchants. (Max Bender/Unsplash)SummaryShow
  • A serious vulnerability in BTCPay Server has been exploited, leading to the theft of funds from Lightning nodes running LND, prompting urgent updates to version 2.4.2 or server shutdowns.
  • The security flaw granted unauthorized access to LND “.macaroon” credential files, allowing attackers to control affected Lightning nodes and empty their channels, although BTCPay's on-chain wallets were not affected.
  • Notable victims, including hardware-wallet manufacturer Foundation and the bitcoin publication Citadel21, reported that their Lightning nodes were compromised, as BTCPay and the Bitcoin Red Team investigate and prepare a comprehensive report on the incident.

This week has been particularly challenging for Bitcoin software, especially for merchants utilizing the BTC$64,968.63 Lightning network, which facilitates quick and cost-effective transactions.

On Friday, attackers exploited a critical vulnerability in BTCPay Server, which exposed the credentials safeguarding Lightning nodes, as reported by the team in an X post.

BTCPay confirmed that funds were taken and urged users running LND — the predominant software for Lightning nodes — to either update to version 2.4.2 or take their servers offline immediately.

The organization has not yet revealed how many users were affected or the total amount of bitcoin stolen.

The vulnerability enabled remote attackers to gain access to “.macaroon” files, which are credentials that allow software to interact with an LND Lightning node. BTCPay noted that the attacks specifically targeted these credential files, which could be exploited to seize control of the node and transfer funds.

Among the victims was Foundation, a hardware-wallet producer. CEO Zach Herbert confirmed that attackers drained the company's BTCPay Lightning node overnight, shutting down its channels and taking the funds, while its BTCPay on-chain hot wallet remained unaffected.

Citadel21, a bitcoin publication run by the pseudonymous commentator hodlonaut, also indicated that its Lightning node had been compromised, although it reported that only a small amount of money was stored there.

This vulnerability was previously flagged to BTCPay by members of the Bitcoin Red Team — a group of developers that recently began using AI models to analyze Bitcoin codebases and has reported numerous findings across various projects this week.

Read More: Bitcoin developers flag 85 critical bugs in an "extremely bad" situation.

BTCPay acknowledged the contributions of Red Team members Craig Raw, Rob Hamilton, Calle, and Evan Kaloudis for responsibly reporting and analyzing the issue.

The group's rationale for promptly disclosing their findings was to prevent others from independently discovering the same bugs, as attackers had already begun exploiting this vulnerability on live servers before BTCPay issued a public warning.

BTCPay has since refined its initial alert, clarifying that its standard on-chain wallets, including hot wallets generated within BTCPay, are not impacted by the credential vulnerability.

However, funds held in LND's own on-chain wallet may still be at risk, as they are tied to the compromised Lightning node.

BTCPay has yet to provide technical specifics about the vulnerability, citing the need for operators to have adequate time to implement patches. A detailed postmortem is expected in the coming days.