BTCPay restricts remote Lightning access after attackers steal funds

1 day ago

BTCPay Server has temporarily restricted nationalist distant connections to Lightning Network nodes moving Lightning Network Daemon (LND) bundle aft attackers exploited a captious vulnerability to get credentials and determination funds. 

BTCPay said the regularisation prevents outer wallets specified arsenic Zeus from connecting done a BTCPay Server domain oregon Tor bulb code connected Docker deployments. BTCPay said Lightning payments tin proceed and that it plans to reconstruct the remote-access enactment erstwhile it considers it safe. 

Version 2.4.2 installs LND mentation 0.21.1 and automatically regenerates the macaroon credentials connected modular BTCPay installations. The task advised operators to cheque for unauthorized payments, unexpected transmission closures, unfamiliar peers and discrepancies successful their onchain oregon Lightning balances.

The BTCPay breach is the latest information incidental involving wide utilized Bitcoin products, pursuing a Coldcard hardware-wallet flaw linked to more than $100 cardinal successful confirmed losses. The abstracted incidents affected bundle surrounding Bitcoin alternatively than the network’s underlying protocol.

Update automatically rotates Lightning credentials

BTCPay said the vulnerability allowed an unauthenticated distant attacker to get “macaroon” credential files utilized to power LND, an implementation of the Lightning Network. The task said the exposed credentials could let attackers to instrumentality power of an LND node and determination its funds.

According to the project’s information advisory, mentation 2.4.2 installs LND mentation 0.21.1 and automatically regenerates macaroon credentials connected modular BTCPay installations. It advised operators to cheque for unauthorized payments, unexpected transmission closures, unfamiliar peers and discrepancies betwixt their records and onchain oregon Lightning balances. 

Related: Coldcard exploit pushes July losses to $247M arsenic second-worst period of 2026

BTCPay besides said operators exposing LND done their ain reverse proxy, Tor service, forwarded port, oregon different way extracurricular BTCPay indispensable rotate their credentials separately. The task said installing the update does not adjacent entree routes managed independently by the operator. 

At slightest 2 operators publically reported losses. Foundation CEO Zach Herbert said the hardware-wallet company’s Lightning node was drained overnight. He later clarified that its blistery wallet was unaffected, portion its Lightning channels were closed and the funds swept. 

Bitcoin work Citadel21 also reported that its Lightning node had been swept. Neither relation disclosed the magnitude lost. 

Magazine: 10 weirdest things ever tokenized... including farts

Cointelegraph is committed to independent, transparent journalism. This quality nonfiction is produced successful accordance with Cointelegraph’s Editorial Policy and aims to supply close and timely information. Readers are encouraged to verify accusation independently.

View source