The vulnerability has already been exploited in the real world; BTCPay demands an immediate upgrade to 2.4.2
Open-source Bitcoin ($BTC) payment processing tool BTCPay Server has suffered a major security vulnerability. The official confirmed that attackers have begun exploiting the related weaknesses to obtain access credentials for some Lightning Network nodes, and there have been cases of funds being moved. The team urgently requests that all users immediately upgrade to BTCPay Server 2.4.2. Merchants who cannot complete the update right away should temporarily shut down their servers to avoid continuing exposure to attack risk.
Source: X/@BtcpayServer BTCPay Server confirms that attackers have begun exploiting the related weaknesses to obtain access credentials for some Lightning Network nodes, and there have been cases of funds being moved
BTCPay Server is a self-hosted Bitcoin payment system commonly used by merchants. It can directly receive BTC and Lightning Network payments, and merchants can manage their nodes, wallets, and receiving workflows themselves. This architecture gives businesses control over asset custody; the security of the server and nodes directly affects the safety of funds. This vulnerability gives attackers an opportunity to obtain sensitive credentials for Lightning nodes and further operate the related funds.
The official authority has not yet published complete technical details of the vulnerability, the time when the attack began, the exact number of affected servers, or the total amount of stolen funds. Early security advisories mainly warned that the vulnerability could lead to loss of funds. Subsequent investigations confirmed that attackers had actually exploited the vulnerability to obtain credentials and transfer funds. The issue was reported by members of the Bitcoin Red Team, and it has now been patched in the latest version.
The attack targeted Lightning credentials; the core risk is high-privilege Macaroons
The main risk in this incident centers on the remote access mechanism of the Lightning Network Daemon (LND). LND uses authorization credentials called Macaroons to manage node operation permissions at different levels, including querying information, managing payments, and other node functions. If a high-privilege Macaroon is leaked, an attacker could use it to gain the ability to remotely control Lightning nodes.
BTCPay Server therefore requires affected users to regenerate the relevant Macaroon credentials after completing the upgrade and to rebuild macaroons.db. Merchants using other Lightning backends should also update their connection credentials and verification information to reduce the risk that attackers already obtained from old credentials.
Version 2.4.2 also includes LND 0.21.1. For merchants using a standard BTCPay deployment environment, upgrading will automatically regenerate some Macaroons. The official still recommends that users verify the server version after updating themselves and check whether the related credentials have indeed been updated.
Merchants should also check recent node activity, including unauthorized Lightning payments, abnormal channel closures, unfamiliar node connections, and changes in on-chain and Lightning balances. If an attacker had already obtained valid credentials before the system was patched, simply updating the software may not fully eliminate the subsequent risks caused by the exposure of existing credentials.
Temporarily block the remote LND function; restrict external wallet connections
To reduce the risk of the vulnerability being exploited continuously, BTCPay Server has temporarily limited remote access to LND nodes via publicly accessible domains. For merchants deploying with Docker standard setups, they can currently no longer directly connect their nodes to remote endpoints such as Zeus—via the BTCPay Server domain or Tor onion address—using the original method.
This restriction mainly affects remote management functions; the merchant’s Lightning payment receiving can continue to operate. The BTCPay team said that they will assess whether to restore remote access functionality after confirming the security of the relevant connection mechanisms.
Users who previously set up on-chain hot wallets directly in a BTCPay Server environment have also been asked to increase their vigilance. Official guidance recommends that affected users assess transferring funds to a new wallet, recreating the mnemonic phrase, addresses, and sensitive credentials, and reducing the security risk that may arise from potentially compromised data in the original environment.
The handling of this incident therefore covers multiple aspects, including upgrading to a secure version, revoking or regenerating old credentials, checking transactions and node logs, and—depending on the actual deployment setup—rebuilding the wallet. If a merchant finds abnormal transactions, they should also preserve server logs and related data as soon as possible to help with subsequent investigations into the flow of funds.
As the risk of self-hosted payments emerges, the merchant’s server becomes a key security line of defense
BTCPay Server has long focused on open-source, self-custody, and self-managed receiving as its main features. Merchants can directly control the Bitcoin and Lightning payment processes, reducing reliance on centralized payment processors. In return, server maintenance, software updates, access permissions, and node credential management also become security responsibilities that merchants must handle themselves.
This incident shows that the attack surface of the Bitcoin payment system includes components such as the web server, the Lightning management interface, authorization credentials, and hot wallets. Once an attacker gains sufficient privileges, they may be able to operate the node or transfer funds. Even if the underlying Bitcoin network itself was not compromised, users could still suffer losses due to vulnerabilities in surrounding software.
BTCPay Server has not yet published a complete incident report. The causes of how the vulnerability was formed, the actual scope of victims, the methods used by attackers, and cumulative losses are still pending further investigation. At this stage, the official lists upgrading to 2.4.2 as the top priority and requires operators who cannot update immediately to pause their systems.
A recent Coldcard security incident has brought renewed attention to hardware wallets and private key generation mechanisms. Meanwhile, the BTCPay Server vulnerability extends the risk to merchants’ payment infrastructure. From personal wallets to enterprise receiving systems, securing crypto assets involves many areas such as hardware, software, credential management, and server operations. Any weakness in any part could become an entry point for attackers to gain control of funds.
Further reading: Coldcard cold wallet hacked—loss exceeds $130 million; attackers expanded to 15 people
“Open-source Bitcoin payment project BTCPay has a major vulnerability! Urgently calls on merchants to update their systems” — this article was first published on “Crypto City”
