BTCPay Server exploit drains Lightning nodes running LND—urgent update to 2.4.2
BTCPay Server reported a critical attack that drained Lightning payment nodes running LND. The flaw let an unauthenticated attacker access LND “.macaroon” credential files. With those credentials, attackers could take control of affected Lightning nodes, move funds, and sweep Lightning channels.
BTCPay urged operators running LND to update immediately to version 2.4.2 or take servers offline. The team said it has reviewed attacks and confirmed stolen funds, but did not disclose how many users were impacted or the total bitcoin amount taken. Hardware-wallet maker Foundation and the bitcoin outlet Citadel21 (hodlonaut) both said their Lightning nodes were swept; Foundation noted its BTCPay on-chain hot wallet was not affected.
BTCPay later clarified that its standard on-chain wallets, including on-chain hot wallets generated inside BTCPay, were not impacted by this credential flaw. However, funds sitting under a compromised Lightning node could still be at risk because they are controlled via that Lightning setup. BTCPay and the Bitcoin Red Team are investigating and plan a full postmortem.
The incident follows Red Team’s earlier warnings, highlighting how quickly Lightning infrastructure exploits can turn into real fund losses. For traders, this is a reminder that operational/security headlines can drive short-term risk sentiment even when BTC spot markets are not directly affected.
Neutral
This is a serious Lightning infrastructure security incident, but it targets BTCPay Server deployments running LND rather than the broader BTC protocol or major spot/liquidity venues. BTCPay indicated that its standard on-chain wallets (including BTCPay-generated hot wallets) were not affected, which limits spillover risk into BTC’s immediate price discovery.
Traders may see short-term “risk-off” reactions because demonstrated key/credential compromise typically raises concerns about custody safety, operational security, and the reliability of payment rails. Similar headlines in past crypto history—such as rapid exploitation of infrastructure components (wallet software, node management tools, or bridge-related systems)—often trigger temporary volatility and higher implied risk premiums, even when overall market fundamentals remain unchanged.
However, the lack of disclosed total stolen amount and the focus on a specific node credential mechanism suggest the macro market impact is likely contained. In the short term, market attention will concentrate on Lightning/node operators updating to LND 2.4.2 and any further disclosures from BTCPay/Red Team. Over the longer term, repeated security incidents can slightly weigh on sentiment toward less-audited infrastructure layers (like payment-node tooling), but without evidence of systemic BTC-level compromise, the expected effect on sustained price direction is likely neutral.