BTCPay Server Issues Urgent Patch After Wallet Drains
BTCPay Server has released a critical update following a security bug that allowed attackers to drain merchant Lightning wallets.

BTCcoinbeat.news
BTC/USD live chart
LIVEBTCPay Server has rolled out version 2.4.2 to fix a serious vulnerability that left LND credential files exposed to remote access. Attackers used this hole to gain unauthorized control over merchant Lightning nodes and drain funds. The bug centers on macaroon files, which act as digital keys for node permissions. If these keys fall into the wrong hands, attackers can interact with a node as if they were the owner.
It is important to clarify that this was not a flaw in the Bitcoin protocol itself. The Bitcoin blockchain remains secure and functioned as intended. Instead, the issue was specific to the server software and how certain BTCPay setups managed their configuration. This serves as a stark reminder that self hosting payment infrastructure requires constant maintenance and diligent security practices.
In response to the thefts, the project team is offering a recovery bounty to incentivize the return of stolen assets. The reward is set at 10% of any recovered funds, with a maximum cap of 3 BTC. While this bounty aims to provide a path toward recovery, the most critical step for any merchant currently using this software is to update their system to version 2.4.2 immediately.
This incident highlights the trade off of self sovereignty in crypto payments. While running your own node eliminates the need for a middleman, it places the full burden of security on the operator. Anyone managing a node should treat software updates, credential management, and system monitoring as a high priority to protect their funds from evolving threats.
Prices update live from CoinMarketCap. Market data, not financial advice.
Market sentiment
Be the first to react
▍Comments (0)
No comments yet. Start the conversation!


