Foundation and Citadel21 have reported that their Lightning nodes were drained, though specific details on the total amount stolen and number of affected operators remain undisclosed.

Foundation and Citadel21 have reported that their Lightning nodes were drained, though specific details on the total amount stolen and number of affected operators remain undisclosed.

Foundation CEO Zach Herbert confirmed that his company’s hardware-wallet Lightning node was emptied overnight but noted that its hot wallet remained unaffected. Citadel21 also disclosed that its Lightning node had been drained, without revealing the exact amount involved.

BTCPay Server has implemented temporary restrictions on public remote connections to Lightning Network nodes running LND software due to a security vulnerability exploited by attackers who obtained credentials and moved funds. This measure prevents external wallets from connecting through BTCPay Server domains or Tor onion addresses on Docker deployments, allowing Lightning payments to continue while the project plans for safe re-introduction of remote-access options.

Operators are advised to check for unauthorized payments, unexpected channel closures, unfamiliar peers, and discrepancies in their balances. Version 2.4.2 of BTCPay installs LND version 0.21.1 and automatically regenerates macaroon credentials on standard BTCPay installations. Those using LND through reverse proxies, Tor services, forwarded ports, or independently managed access routes need to rotate their credentials separately.

These incidents follow other security events in the Bitcoin ecosystem, such as a Coldcard hardware-wallet flaw linked to losses of more than $100 million and another reported loss from Citadel21.


Written by Daniel Brooks
Security Desk

Share