Cryptelio

Hacks & Exploits

BTCPay Server Issues Urgent Update Following Fund Theft Exploit

Cryptelio Editorial Published 8 Aug 2026 · 12:04 UTC

BTCPay Server has issued an urgent warning to its users after confirming that attackers exploited a critical vulnerability to steal funds from those using versions prior to 2.4.2. The self-hosted Bitcoin payment processor released version 2.4.2 to address this flaw, which allowed unauthorized access to .macaroon credential files for LND, a widely used implementation of the Lightning Network.

The vulnerability enabled attackers to gain full control of an LND node, facilitating the direct movement of funds out of the node. BTCPay Server has confirmed that funds were stolen and is currently withholding technical details to give operators time to update their systems. Users are strongly advised to update their BTCPay Server to version 2.4.2 by navigating to the Admin Dashboard and verifying the version string in the footer.

This risk specifically affects deployments using LND, while other Lightning setups and non-Lightning users are not exposed to credential theft. Nonetheless, BTCPay Server has recommended that all users update their systems. The update will automatically regenerate macaroons, enhancing security. Users unable to implement the patch immediately have been advised to take their servers offline and review node activity for any suspicious behavior.

This incident follows another significant security breach involving Coldcard users, where approximately 1,719 Bitcoin (BTC), valued at around $111 million, was reported stolen. Both incidents highlight vulnerabilities in the tools surrounding the Bitcoin protocol rather than flaws within the protocol itself.

FAQ

What is the critical vulnerability in BTCPay Server?

The critical vulnerability allowed attackers to exploit unauthorized access to .macaroon credential files for LND, enabling them to gain full control of an LND node and steal funds.

Which versions of BTCPay Server are affected by this vulnerability?

Versions prior to 2.4.2 of BTCPay Server are affected by this vulnerability.

How can users protect themselves from this vulnerability?

Users are strongly advised to update their BTCPay Server to version 2.4.2 by checking the Admin Dashboard and verifying the version string in the footer.

What should users do if they cannot update immediately?

Users who cannot implement the patch immediately should take their servers offline and review node activity for any suspicious behavior.

Are non-Lightning users affected by this vulnerability?

No, the risk specifically affects deployments using LND. Other Lightning setups and non-Lightning users are not exposed to credential theft, but BTCPay Server recommends all users update their systems.

Read story →