BTCPay restricts remote Lightning access after attackers steal funds
Reported by Cointelegraph · AI-assisted summary by ChikoCorp AI News Desk

AI-generated summary based on the linked source; not independently verified. This is not investment advice. Verify market-moving details at the original publisher before acting. See our editorial policy, AI content policy, and financial disclaimer.
Summary
BTCPay Server has temporarily restricted public remote connections to Lightning Network nodes running Lightning Network Daemon (LND) software after attackers exploited a critical vulnerability to access credentials and steal funds. The restriction blocks external wallets like Zeus from connecting remotely via BTCPay Server domains or Tor addresses on Docker deployments. BTCPay installed version 2.4.2, which updates LND to v0.21.1 and automatically regenerates the macaroon credentials to mitigate the issue.
Why it matters
This development impacts users running BTCPay Server Lightning nodes as it limits remote wallet connectivity, currently restricting popular external wallet access methods. The security breach underscores ongoing risks in the Bitcoin software ecosystem and highlights the importance of quick credential rotation to prevent further fund loss. The BTCPay Team’s response aims to restore safe remote access and reassure users of continued Lightning payments capability.
Key context
The vulnerability involved unauthenticated remote attackers obtaining “macaroon” credential files controlling LND nodes, allowing them to seize funds and manipulate channels. The breach follows other recent Bitcoin software security incidents, such as a Coldcard hardware wallet flaw that caused over $100 million in losses. BTCPay recommends operators check for unauthorized activity and rotate credentials especially if using reverse proxies or other non-standard access methods.
Key numbers and entities
BTCPay Server, Lightning Network Daemon (LND) v0.21.1, and the Zeus wallet are key entities. At least two operators publicly reported losses, including Foundation CEO Zach Herbert’s hardware-wallet company, and Bitcoin publication Citadel21. No specific loss amounts were disclosed.
What remains unclear
The source does not specify the total scale of losses or how many operators were affected beyond the two public cases. It also does not detail exactly when remote access restrictions will be lifted or the precise vulnerability that was exploited.