Critical LND Flaw Drains BTCPay Server Funds as Bitcoin Infrastructure Faces Crisis

Key Takeaways

Attackers exploited an unauthenticated remote vulnerability in LND software via BTCPay Server, draining funds from merchants including Foundation and Citadel21. The Bitcoin Red Team disclosed the flaw, prompting urgent updates to version 2.4.2 to secure e

Woofun AI reports that a critical security breach targeted BTCPay Server, draining funds from merchants utilizing the Lightning network for instant, low-cost BTC transfers. This incident exacerbates a rough week for bitcoin infrastructure, as attackers exploited a vulnerability in LND, the most widely used software for operating Lightning nodes, to steal credentials. The Bitcoin Red Team disclosed the flaw after observing active exploitation, forcing immediate remediation efforts across the ecosystem to prevent further unauthorized access to node operations and fund transfers.

The technical root of the breach allowed an unauthenticated remote attacker to obtain ".macaroon" files, which serve as critical credentials granting software permission to interact with an LND Lightning node. Following the discovery, BTCPay confirmed that funds were stolen and instructed all users running LND to update immediately to version 2.4.2 or take their servers offline to mitigate risk. The attacks specifically targeted these credential files, enabling perpetrators to take control of the nodes and move funds without authorization. Late on Friday, the team highlighted that the exposure was severe enough to warrant immediate action, as the compromised credentials provided full administrative access to the Lightning node's financial operations.

Specific victims emerged quickly, highlighting the real-world impact of the vulnerability. Hardware-wallet maker Foundation was among the affected entities, with Chief Executive Zach Herbert stating that attackers drained the company's BTCPay Lightning node overnight, closing its channels and sweeping the funds.

Notably, Foundation confirmed that its BTCPay on-chain hot wallet remained untouched by the intrusion. Similarly, Citadel21, the bitcoin publication run by pseudonymous commentator hodlonaut, reported that its Lightning node had been swept, though the organization noted that little money was held there at the time of the attack. These incidents underscore the severity of the exploit, demonstrating that even high-profile entities with robust security practices were vulnerable to credential theft.

Woofun AI data shows that the Bitcoin Red Team, which has been pointing AI models at bitcoin codebases this week, had already reported the vulnerability to BTCPay before it was exploited in the wild. The team, comprising members Craig Raw, Rob Hamilton, Calle, and Evan Kaloudis, credited with responsibly disclosing the issue and helping analyze it, has filed thousands of findings across hundreds of projects since beginning its audit campaign. The group stated that they published findings quickly because external actors would inevitably arrive at the same bugs, and by the time BTCPay's public warning went out, attackers were already exploiting this specific flaw against live servers. This rapid disclosure strategy reflects the broader trend of using AI-driven audits to identify critical bugs, with the Red Team recently flagging 85 critical bugs in what they described as an 'extremely bad' situation for the industry.

BTCPay later narrowed the scope of the alert, clarifying that its standard on-chain wallets, including hot wallets generated inside BTCPay, are not affected by the credential flaw.

However, the exposure applies specifically to deployments using LND, and funds held inside LND's own on-chain wallet remain at risk because they sit under the compromised Lightning node. The project has not yet published technical details of the vulnerability, stating that operators need time to patch their systems effectively. A full postmortem is due in the coming days, which will likely provide deeper insights into the attack vector and help developers strengthen future defenses against similar credential-based exploits.

Comments

Me
Replying to @User
0/800

No comments yet.

Notifications

Sign in to view messages
View all messagesManage subscriptions