Critical BTCPay Server Flaw Lets Attackers Drain Bitcoin Lightning Nodes
A security flaw in BTCPay Server, a popular self-hosted payment processor for Bitcoin, has been exploited by attackers to drain funds from Bitcoin Lightning Network nodes. The vulnerability affected all versions before 2.4.2 and exposed LND (Lightning Network Daemon) credential files, giving attackers the access they needed to steal funds directly from victims' payment channels.
At least two node operators have reported that their Lightning channels were emptied before a public warning about the flaw was issued, meaning attackers were exploiting the weakness before businesses had a chance to patch or protect themselves.
While this incident is specific to businesses running BTCPay Server for cryptocurrency payments, it highlights a broader lesson: self-hosted financial infrastructure carries real security responsibilities. Businesses that accept Bitcoin or other cryptocurrencies through self-managed software must stay on top of updates, as delays in patching can directly translate into stolen funds.