Critical vulnerability in BTCPay Server is already being exploited: attackers gain access to LND node credentials and can withdraw funds from Lightning channels, while the vulnerability itself is in BTCPay—not in LND or Bitcoin—developers urge to update immediately to v2.4.2 or disable the server
For BTC this is not a fundamental threat to the protocol, but it is a serious blow to self-hosted Lightning infrastructure—especially because the stolen credentials after the patch should be considered compromised; the market can survive such a bug, but a forgetful node operator—maybe not
#LightningNetwork #BTCPay #LND #CyberSecurity #BinanceSquare