started · updated
BTCPay Server issues emergency update following active exploitation of critical vulnerability
BTCPay Server, an open-source Bitcoin payment processor, has issued an emergency security alert following the discovery of a critical vulnerability being actively exploited by attackers. The flaw allows unauthorized access to Lightning Network nodes, specifically targeting implementations using the Lightning Network Daemon (LND).
Technical reports indicate that attackers have been able to steal '.macaroon' credential files, granting them control over affected nodes and the ability to drain liquidity channels. Notable entities reported as victims include the hardware wallet manufacturer Foundation and the publication Citadel21, both of which experienced the emptying of their Lightning nodes. One source noted that the Foundation CEO confirmed the Lightning node was drained, though main wallets remained secure.
Separate reports highlight a secondary vulnerability involving the Greenfield API, where a flaw in the authentication mechanism allowed attackers to bypass two-factor authentication (2FA) using only an email and password.
BTCPay Server has released version 2.4.2 to patch these issues and urges all administrators to update immediately or shut down their servers to prevent further loss of funds. Beyond the software update, developers recommend that users rotate Lightning Network authentication strings, refresh credentials, and move any funds from hot on-chain wallets into newly created ones to ensure complete security.
Entities
BTCPay Server · Bitcoin Red Team · Citadel21 · Foundation · LND · Lightning Network
Claims
What the coverage asserts, and how well corroborated each claim is across sources.
- [● 3 SOURCES] The hardware wallet manufacturer Foundation had its Lightning node drained during the attack. koinbulteni.com · www.spacemoney.com.br · cryptonomist.ch
- [● 2 SOURCES] The vulnerability involves the ability to bypass two-factor authentication (2FA) via the Greenfield API. www.nadanews.com · www.cryptopolitan.com
- [● 4 SOURCES] Users are advised to rotate Lightning Network authentication strings and recreate macaroons.db files. bitcoinethereumnews.com · en.coin-turk.com · journalducoin.com · coinedition.com
- [● 2 SOURCES] The publication Citadel21 also reported its Lightning node was targeted in the attack. koinbulteni.com · cryptonomist.ch
- [● 5 SOURCES] Attackers exploited the vulnerability to access '.macaroon' credential files to control Lightning Network nodes. koinbulteni.com · livecoins.com.br · news-krypto.de · www.spacemoney.com.br · www.btc-echo.de
- [● 13 SOURCES] BTCPay Server released version 2.4.2 to address a critical vulnerability. koinbulteni.com · bitcoinethereumnews.com · www.nadanews.com · en.coin-turk.com · journalducoin.com · +8 more
- [● 5 SOURCES] The Bitcoin Red Team identified and reported the vulnerability. koinbulteni.com · bitcoinethereumnews.com · en.coin-turk.com · journalducoin.com · coinedition.com
- [● 2 SOURCES] Standard on-chain wallets within BTCPay Server were not affected by the credential vulnerability. koinbulteni.com · news-krypto.de