Critical BTCPay Server Flaw Leads to Stolen Bitcoin Funds
BTCPay Server operators are scrambling to patch a dangerous security vulnerability that allows attackers to drain funds from Lightning nodes.
BTCcoinbeat.news
BTC/USD live chart
LIVEThe team behind the Bitcoin payment processor BTCPay Server has issued an urgent warning after confirming that attackers are actively exploiting a critical software flaw. This vulnerability specifically targets users running versions older than 2.4.2, allowing bad actors to gain unauthorized access to LND credential files. Once these files are compromised, attackers can seize control of a node and drain Bitcoin directly from it.
The project confirmed that actual theft has occurred and is currently withholding technical details to give operators a chance to secure their systems. Anyone managing a BTCPay instance with LND should immediately navigate to their Admin Dashboard to update to version 2.4.2. The update process automatically regenerates the necessary security keys. If an immediate update is not possible, the team advises taking servers offline until the patch is applied.
While non Lightning users and those using different payment setups face lower risks, the project still recommends updating all installations to the latest version. Affected operators should also monitor their node activity closely for signs of unauthorized peer connections or unexpected payments. This incident, occurring alongside recent losses involving Coldcard wallets, highlights the ongoing need for extreme caution when using third party tools to manage self custody assets.
Prices update live from CoinMarketCap. Market data, not financial advice.
Market sentiment
Be the first to react
▍Comments (0)
No comments yet. Start the conversation!



