BTCPay Server Flaw Drains Lightning Nodes

BTCPay flaw shown as a cracked strongbox leaking Bitcoin coins into a lightning bolt

BTCPay Server warned on Friday that a critical vulnerability is already being exploited and can cost users the funds held on their server. The project is pushing an immediate upgrade to version 2.4.2, and telling anyone who cannot patch right away to take the server offline instead. Two known names in the space, hardware maker Foundation and Bitcoin zine Citadel21, had their Lightning nodes swept with channels force-closed.

Key Takeaways

  • BTCPay Server confirms an actively exploited critical flaw and ships version 2.4.2
  • Foundation and Citadel21 had Lightning nodes drained and channels force-closed
  • Neither the number of compromised servers nor the amount stolen is known yet

A Patch Shipped Before the Attack Was Explained

The warning went out through the project’s official account late in the week, in wording that leaves little room for interpretation. A critical vulnerability is under active exploitation and can result in loss of funds.

The instruction set is short. Open the admin dashboard, run the update, then confirm that the 2.4.2 version string shows in the footer. The full guidance went out on the project’s own account on X, which tells operators to shut the server down entirely if the patch cannot be applied on the spot.

What comes after the patch says more than the patch itself. The project wants macaroon credentials replaced, the macaroons.db file recreated, and authentication strings refreshed for every other Lightning backend in the stack.

Any hot onchain wallet generated inside the interface has to be emptied and rebuilt. Integrators also need to move NBXplorer, the wallet-tracking backend, to version 2.6.10. Patching alone does not close this, because the authentication secrets are being treated as already compromised.


BTCPay
Advertisement – investing involves risk.

What the Project Has Not Disclosed Yet

Everything else is still dark. The exact mechanism, the moment the attacks started, how many servers were compromised and how much was actually taken were all unknown when the alert went out.

One clarification did land. The project founder confirmed this is not the two-factor bypass already listed in the changelog, so the root cause sits elsewhere and the technical writeup is still pending. Bitcoin Red Team members are credited with reporting the issue, following the same cautious disclosure pattern as the Coldcard flaw that drained $70M in 41 minutes.

Holding back the details is standard defensive practice. Publishing the anatomy of a live exploit before the fleet is patched simply arms everyone who had not found the vector yet. The trade is uncomfortable for administrators, who have to patch without knowing what they are fixing, and who cannot size their own exposure in the meantime.

The project had not responded to requests for comment when the first reports went out. That silence is consistent with an incident still unfolding rather than one being wrapped up, which is why the guidance leans so heavily on switching the server off.

The timing makes it worse. The disclosure lands a week after the Coldcard incident, whose confirmed losses reach $116 million. Two pieces of Bitcoin infrastructure with strong reputations broke inside a fortnight.


Also on Cryptonomic:


Merchants Are the Target Now

In the near term this hits a specific population. BTCPay Server runs the checkout for merchants and projects that refuse an intermediary and host their own payment rail rather than hand keys to a third party. It is the same trade-off that sits behind the cold wallet versus hot wallet decision, with the security burden landing on the holder.

Foundation and Citadel21 showing up as victims is the uncomfortable part. Both operate well above the average in terms of security hygiene, and their nodes were swept anyway, with channels force-closed.

Over the coming months the episode shifts the self-hosting debate. Holding your own keys removes counterparty risk and hands you the entire operational security load in exchange, and the balance depends on how much attack surface you are willing to maintain yourself.

The structural trend worries more than this single incident. Automated analysis tools keep lowering the cost of finding a flaw, and older or lightly audited crypto infrastructure becomes profitable to hunt, the same logic that let attackers drain $35M from three DeFi protocols in six hours.

One unknown dominates the rest. Until the count of compromised servers is established, nobody can say whether BTCPay Server took a targeted hit on a handful of high-value nodes or a broad sweep of the fleet. The real damage number comes later.

Follow the story on Cryptonomic.

Comments

No comments yet. Why don’t you start the discussion?

    Leave a Reply

    Your email address will not be published. Required fields are marked *