TLDR
- BTCPay Server temporarily blocked external remote connections to Lightning Network nodes after attackers exploited a critical vulnerability
- Attackers obtained “macaroon” credential files used to control LND nodes, allowing them to move funds
- Version 2.4.2 patches the flaw and automatically rotates credentials on standard installations
- Foundation CEO Zach Herbert confirmed his company’s Lightning node was drained overnight
- Bitcoin publication Citadel21 also reported its Lightning node was swept, though neither disclosed amounts lost
BTCPay Server has temporarily blocked public remote connections to Lightning Network nodes after attackers used a critical security flaw to steal funds from at least two operators.
⚠️ALERT: An actively exploited BTCPay Server flaw is draining merchant Lightning nodes.
Attackers can remotely grab credential files from BTCPay deployments running LND and empty the node, with hardware wallet maker Foundation among the confirmed victims, per CoinDesk.
BTCPay… pic.twitter.com/558xdhTbjm
— Coin Bureau (@coinbureau) August 8, 2026
The attack targeted nodes running Lightning Network Daemon software. Attackers exploited the vulnerability to obtain “macaroon” credential files, which are used to control LND nodes. Once they had those credentials, they could move funds freely.
The restriction prevents external wallets like Zeus from connecting through a BTCPay Server domain or Tor onion address on Docker deployments. BTCPay said Lightning payments can still be made and that the remote access option will be restored when it is considered safe to do so.
What the Update Does
BTCPay released version 2.4.2 to address the issue. The update installs LND version 0.21.1 and automatically regenerates macaroon credentials on standard installations.
Operators who route LND through their own reverse proxy, Tor service, or forwarded port outside of BTCPay must rotate their credentials separately. The update does not close access routes managed independently by the operator.
BTCPay advised all operators to check for unauthorized payments, unexpected channel closures, unfamiliar peers, and any balance discrepancies across onchain or Lightning accounts.
Known Victims
Foundation CEO Zach Herbert publicly confirmed his company’s Lightning node was drained overnight. He later clarified the company’s hot wallet was unaffected. The Lightning channels were closed and funds swept.
Bitcoin publication Citadel21 also reported its Lightning node had been swept. Neither operator disclosed the total amount stolen.
The total number of affected operators remains unknown.
This incident follows a separate Coldcard hardware wallet flaw that was linked to more than $100 million in confirmed losses. Both incidents affected software surrounding Bitcoin rather than the Bitcoin network’s underlying protocol.
BTCPay said the two incidents are unrelated. The broader security concerns around Bitcoin infrastructure products have put operators on alert.
BTCPay said it plans to restore remote access functionality once it determines it is safe to do so. No timeline was given.
Operators are urged to install the update immediately and review their node activity for any signs of unauthorized access.







