BlockBeats report: On August 9, BTCPay Server released an emergency security announcement stating that all versions prior to 2.4.2 (including the 2.4.2 candidate version) have a critical vulnerability. It has been confirmed that the vulnerability has been used in real attacks, and user funds have been stolen. The vulnerability may allow an unauthenticated remote attacker to obtain the .macaroon credential file of LND (the Lightning Network implementation), thereby gaining control of the LND node and transferring funds.
Officially confirmed that this vulnerability has been actively exploited, resulting in users’ funds being stolen, and urged users of LND to immediately upgrade to BTCPay Server 2.4.2 and LND 0.21.1. The on-chain wallet itself is not affected by BTCPay Server. The official has not yet disclosed the specific amount stolen.
Public information shows that BTCPay Server is a free, open-source, self-hosted Bitcoin payment processor, focused on providing no-cost, no-intermediary Bitcoin payment solutions for individuals and businesses who value sovereignty. Core contributors to the protocol have estimated that there may be hundreds of thousands of BTCPay Server instances running worldwide. Its main GitHub repository has been downloaded more than 1 million times.
