Lightning Network Vulnerability Leads to Bitcoin Merchant Losses

Lightning Network Vulnerability Leads to Bitcoin Merchant Losses

A critical security flaw in BTCPay Server, exploiting vulnerabilities within Lightning nodes utilising LND software, resulted in significant losses for several merchant operators.

The incident occurred late on Friday and involved attackers gaining control of BTCPay-powered Lightning nodes. These nodes, operating behind the BTCPay platform, were drained of funds due to an exposure of credentials protecting them. This allowed access to “.macaroon” files which facilitated unauthorised control and subsequent movement of Bitcoin assets.

BTCPay Server provides a payment platform relying on the Lightning Network. Foundation, a hardware wallet manufacturer, was also affected by these attacks. The vulnerability itself permitted unauthenticated remote attackers to acquire these crucial “.macaroon” files.

Funds were reported stolen from multiple merchant nodes as a direct result of this breach. BTCPay has confirmed that losses have occurred and immediately advised users to update their systems to version 2.4.2, or alternatively, take the server offline as preventative measure. The vulnerability’s impact centres around LND – the most widely used software for operating Lightning Nodes.

At the time of the incident, Bitcoin was trading at $64,968.63. BTCPay has remained tight-lipped regarding specific figures for the stolen funds, and details on the scale of impacted users are currently unavailable. It is important to note that the company’s on-chain hot wallet remains unaffected by these actions.

The situation underscores the ongoing security challenges associated with Lightning Network implementations, particularly concerning access control and credential management. BTCPay’s rapid response, coupled with the recommendation for system updates, highlights a commitment towards remediation efforts within the wider Bitcoin ecosystem.


Written by Daniel Brooks
Security Desk

Share