Loading market data...
Back to Feed
BITCOIN

Another Bitcoin infrastructure exploit hits, this time draining Lightning payment servers

Reported by CoinDesk · AI-assisted summary by ChikoCorp AI News Desk

Published on CryptoNews: Source published: 2 min read
AI-generated editorial illustration for Another Bitcoin infrastructure exploit hits, this time draining Lightning payment servers
AI-generated editorial illustration.
Visit source

AI-generated summary based on the linked source; not independently verified. This is not investment advice. Verify market-moving details at the original publisher before acting. See our editorial policy, AI content policy, and financial disclaimer.

Summary

Attackers exploited a critical vulnerability in BTCPay Server to steal funds from Lightning nodes running LND by gaining unauthenticated access to “.macaroon” credential files. This allowed the attackers to take control of affected Lightning nodes and drain their channels, though BTCPay’s standard on-chain wallets were not impacted. Victims included hardware-wallet maker Foundation and bitcoin publication Citadel21. BTCPay and the Bitcoin Red Team are investigating the incident and preparing a full postmortem.

Why it matters

The exploit affects merchants who accept bitcoin payments through the Lightning Network, a key infrastructure for instant and low-cost bitcoin transfers. The vulnerability undermines the security of LND Lightning nodes operating behind BTCPay Server, which is widely used. The situation has triggered urgent calls for immediate updates or server shutdowns to prevent further losses.

Key context

BTCPay Server users running LND, the most widely used software for Lightning nodes, were specifically vulnerable. The attack exposed “.macaroon” files that act as credentials granting software permission to interact with a Lightning node. The Bitcoin Red Team, a group of developers using AI models to find bugs across bitcoin projects, reported the bug to BTCPay prior to its exploitation. BTCPay has not disclosed the number of affected users or total funds stolen but has clarified that its standard on-chain wallets remain secure.

Key numbers and entities

Entities mentioned include BTCPay Server, Lightning Network Daemon (LND), hardware-wallet maker Foundation led by CEO Zach Herbert, bitcoin publication Citadel21, and the Bitcoin Red Team developers Craig Raw, Rob Hamilton, Calle, and Evan Kaloudis. No specific figures on the amount stolen or number of victims were provided.

What remains unclear

BTCPay has not published technical details of the vulnerability or disclosed how many users were affected or how much bitcoin was stolen. A full postmortem and more details are expected to be released in the coming days. The precise scope of compromise regarding LND's on-chain wallets versus BTCPay's standard wallets remains partially detailed without quantified impact.

Read the original source

> JOIN THE ALPHA

Get a free crypto news briefing in your inbox. No fake subscriber counts — just the latest source-backed headlines we cache.

>
[ENCRYPTED][NO_SPAM][UNSUBSCRIBE_ANYTIME]