BTCPay Server Vulnerability Leads to Stolen Bitcoin Funds
A critical flaw in BTCPay Server software allowed attackers to drain funds from Bitcoin Lightning nodes.

BTCcoinbeat.news
BTC/USD live chart
LIVEBTCPay Server recently disclosed a critical security vulnerability that affected all versions of its software prior to 2.4.2. Attackers used this flaw to remotely access credential files and take control of Lightning nodes. Once inside, they were able to move funds and close channels belonging to unsuspecting operators.
Prominent Bitcoin projects including Foundation and Citadel21 confirmed their nodes were compromised during the attack. While the issue primarily impacts Lightning channels and LND wallets, the team clarified that standard on chain hot wallets managed by the server remain unaffected for most users.
Simply updating to the latest software version is not enough to stop the threat. Because stolen credentials may still be active, the project team urges all node operators to rotate their keys immediately. Users should carefully audit their nodes for unauthorized transactions, strange peers, or unexpected channel closures.
The vulnerability was identified and reported by the Bitcoin Red Team, a developer group using AI to scan codebases for security gaps. This incident serves as a sharp reminder for self hosted node operators to monitor their security configurations and stay current with all software patches.
Prices update live from CoinMarketCap. Market data, not financial advice.
Market sentiment
Be the first to react
▍Comments (0)
No comments yet. Start the conversation!


