BTCPay Server Restricts Remote Lightning Access Following Credential Exploit
BTCPay Server has temporarily limited public remote connections to Lightning Network nodes utilizing Lightning Network Daemon (LND) software. This action follows an exploit where attackers leveraged a critical vulnerability to acquire credentials and transfer funds.
The restriction impacts external wallets, such as Zeus, preventing them from connecting via a BTCPay Server domain or Tor onion address on Docker deployments. BTCPay indicated that Lightning payments remain operational and that the remote-access option will be reinstated once security is assured.
Vulnerability Details and Mitigation
Version 2.4.2 of BTCPay Server integrates LND version 0.21.1 and automatically regenerates macaroon credentials in standard BTCPay installations. The project recommended that operators verify their systems for unauthorized payments, unexpected channel closures, unrecognized peers, and inconsistencies in their on-chain or Lightning balances.
BTCPay stated that the vulnerability allowed an unauthenticated remote attacker to obtain “macaroon” credential files, which are used to control LND, an implementation of the Lightning Network. The project explained that these exposed credentials could enable attackers to gain control of an LND node and move its associated funds.
BTCPay also advised operators who expose LND through their own reverse proxy, Tor service, forwarded port, or other independent routes to rotate their credentials separately. The project clarified that installing the update does not close access routes managed independently by the operator.
Broader Security Context and Reported Losses
This incident marks another security event involving widely used Bitcoin-related products, occurring after a vulnerability in the Coldcard hardware wallet was linked to over $100 million in reported losses. Both incidents affected software supporting Bitcoin rather than the fundamental protocol of the network.
At least two operators publicly reported financial losses. The CEO of Foundation, Zach Herbert, stated that the company's Lightning node had been drained. He later clarified that while its hot wallet remained unaffected, its Lightning channels were closed and the funds were swept. Bitcoin publication Citadel21 also reported that its Lightning node had been swept. Neither operator disclosed the specific amounts lost.