Bullish

BTCPay Server LND Credential Leak Leads to Fund Theft

2026-08-09 13:57

Severe vulnerabilities in BTCPay Server LND nodes caused credential leaks and fund theft. Public remote connections are temporarily restricted while security patches are deployed.

Woofun AI reports that BTCPay Server has suspended public remote connections for Lightning Network Daemon (LND) nodes following a security breach. Attackers exploited severe vulnerabilities to steal credentials and transfer funds, impacting providers such as Foundation and Citadel21. While external wallet connectivity via domain or Tor addresses is blocked, Lightning Network transactions continue to operate. The service provider confirmed that Version 2.4.2 will integrate LND 0.21.1 and automatically regenerate macaroon credentials to resolve the issue.

WOOFUN AI

Impact Assessment · Quick Read

The exposure of LND credentials highlights critical risks in self-custodial infrastructure, potentially eroding trust in decentralized payment processors. Although Bitcoin itself remains unaffected, the incident underscores the vulnerability of node operators to remote exploitation. Users may face temporary friction in wallet synchronization, but the rapid patch deployment suggests limited long-term disruption to the Lightning Network ecosystem.
Generated by WOOFUN AI · For reference only, not investment advice

Comments

Me
Replying to @User
0/800

No comments yet.

Notifications

Sign in to view messages
View all messagesManage subscriptions