Subscribe Now
Trending News

Blog Post

Hackers Just Drained Lightning Nodes Through BTCPay Server — And Your “Secure” Setup Is Next
News

Hackers Just Drained Lightning Nodes Through BTCPay Server — And Your “Secure” Setup Is Next 

Quick Summary

Your Lightning node is a loaded gun, and hackers just pulled the trigger. A critical BTCPay Server vulnerability let unauthenticated attackers steal LND credential files and drain Lightning channels — live, in the wild, before the public alert even went out. Hardware wallet maker Foundation and Bitcoin publication Citadel21 both got swept overnight. Bitcoin didn’t flinch. You should.

What Happened

On August 7, 2026, BTCPay Server confirmed the worst kind of bug: a critical vulnerability actively being exploited against live servers. Attackers reached in and grabbed .macaroon files — the credential tokens that give software permission to control an LND Lightning node — without logging in, without any password, remotely.

Whoever holds your macaroons controls your node. And the attackers used them to close channels and sweep the funds.

The official warning was brutally direct:

"There is a critical vulnerability being actively exploited on BTCPay Server, which can result in the loss of funds."

BTCPay founder Nicolas Dorier didn’t sugarcoat it either:

"This release contains fix of a critical vulnerability that is being actively exploited. You need to update as fast as you can."

The victims nobody is talking about

Foundation — the company behind the Passport hardware wallet — had its BTCPay Lightning node drained overnight. CEO Zach Herbert confirmed the attackers closed the company’s channels and swept the funds. Only the Lightning exposure was hit; their on-chain hot wallet survived.

Citadel21 — the Bitcoin publication tied to pseudonymous commentator hodlonaut — also reported its Lightning node swept clean, noting thankfully that little was held there.

These aren’t retail newbies. A hardware wallet company got robbed running its own infrastructure. If they can get drained, what do you think is happening to every rando running a BTCPay server for their store?

Who caught the bug

Credit where it’s due: the Bitcoin Red Team — a group including Craig Raw (Sparrow Wallet), Rob Hamilton, Calle, and Evan Kaloudis (ZEUS wallet) — found the flaw and disclosed it to BTCPay before it went public. Their stated reasoning says everything about this ecosystem: others will find the same bugs. They were right. By the time the alert went out, exploitation was already in progress.

FAQ

Am I affected if I use BTCPay Server?
If you run LND behind BTCPay, you’re in the blast radius. BTCPay’s standard on-chain wallets are not directly exposed by this flaw — the vulnerability is specific to LND deployments. But if you run LND, funds in its wallet sit under the compromised node. Update to v2.4.2 now or take the server offline.

I updated. Am I safe?
No. Patching is step one of three. Updating stops new attackers — it does nothing about credentials already stolen. You must also:

  1. Revoke LND macaroons at the node level (this destroys the root signing key, it doesn’t just delete files)
  2. Move funds from any BTCPay-generated on-chain hot wallet and recreate it

Is Bitcoin broken?
Bitcoin’s price barely reacted — it held the $64K–$65K zone while this was unfolding. The base layer was never touched. This is an attack on the convenience layer people bolt on top: Lightning nodes, merchant servers, hot wallets. Bitcoin doesn’t need your trust. Your infrastructure does.

The Lesson Nobody Wants To Hear

Every time you run a hot wallet, a Lightning node, or a merchant server, you are running a bank — with all the attack surface that comes with it. The Coldcard entropy disaster drained ~500 holders of roughly $38 million. Days later, Lightning channels get swept because someone left the macaroon jar unguarded. The pattern isn’t bad luck. It’s the price of convenience.

The people who designed this system keep telling you: not your keys, not your coins. The corollary nobody repeats: your keys are only as safe as the software holding them.

You want to stack sats? Buy your Bitcoin with a coupon that actually respects you — code LOVEISBITCOIN — and keep it on your own hardware. That’s the whole game. Everything else is a trust fall.

If a hardware wallet company’s own Lightning node can get drained overnight — what exactly is sitting in your hot wallet right now, and who’s holding the macaroon jar?

Previous

Hackers Just Drained Lightning Nodes Through BTCPay Server — And Your "Secure" Setup Is Next

Related posts

Leave a Reply

Please authenticate to comment:

Required fields are marked *

⚡ Zap This!

Support this content with sats on Nostr

Zap QR

Lightning Address (tap to copy):

✅ Copied!

Or zap via Nostr client:

🟣 Open in Primal