BTCPay Server confirmed that attackers exploited a critical flaw to steal user funds with any version earlier than 2.4.2 and instructed operators to update immediately.

The self-hosted Bitcoin payment processor released version 2.4.2 to fix the vulnerability. The flaw allowed a remote attacker, without authentication, to obtain .macaroon credential files for LND, a popular Lightning Network implementation.

What should BTCPay Server users do?

The stolen credentials could have given the attacker full control of the LND node. From there, it would be possible to remove the funds directly from the node.

“… We can confirm that attackers exploited this vulnerability. Users were affected and funds were stolen. We are not disclosing technical details at this time because operators still need time to update,” said the team.

There is a critical vulnerability being actively exploited on BTCPay Server, which can result in the loss of funds.

Please update your BTCPayServer to 2.4.2 by going to Admin Dashboard -> Server -> Maintenance -> Update & verify the 2.4.2 version string in the footer.

If you…

— BTCPay Server (@BtcpayServer) August 7, 2026

The risk is specific to deployments that use LND. Other Lightning configurations and users outside of Lightning were not exposed to credentials, but the project maintains the recommendation to update. The on-chain and hot wallets of BTCPay Server itself were not affected.

Operators who use LND must perform the update to version 2.4.2 and also to LND 0.21.1 through the maintenance panel. The update automatically regenerates the macaroons. For those who cannot apply the patch immediately, the guidance was to take the servers offline.

The project also recommended that LND users review node activity to identify unknown peers, unexpected channel closures, and payments that were not made.

A second blow to Bitcoin self-custody

The disclosure comes after another serious security incident. On Friday, Galaxy Research confirmed that 1,719 Bitcoin (BTC), an amount close to US$ 111 million, have been stolen from Coldcard users so far. The company believes total losses will exceed US$ 130 million once all pending cases are verified.

$111 MILLION CONFIRMED STOLEN SO FAR IN COLDCARD EXPLOIT

Thanks to victim reports, we can confirm with high confidence that 1719 BTC has been stolen from Coldcard victims so far

We have many more coins we are vetting for confirmation – we think total losses likely exceed $130m pic.twitter.com/pLfiMQZFyX

— Galaxy Research (@glxyresearch) August 7, 2026

None of the incidents affected the Bitcoin protocol itself. Both revealed weaknesses in the tools built around it.

The article Bitcoin BTCPay payment tool asks for an update after an attack that resulted in funds being stolen was first seen in BeInCrypto Brazil.