The security breach originated from a flaw that exposed LND admin macaroon credentials, granting attackers unauthorized control over associated Lightning wallets. BTCPay Server patched the vulnerability in version 2.4.2 and urged all operators to update immediately. While the project has not disclosed the total volume of stolen funds, users including Foundation and Citadel21 confirmed their nodes were swept by attackers targeting the exposed credentials.
Onchain wallets remained secure throughout the incident, as the exploit was isolated to the Lightning Network implementation. To bolster future security, the BTCPay Server Foundation is implementing rigorous code-scanning procedures. The project also rewarded researchers who identified the flaw before public disclosure, donating 0.21 BTC each to Sparrow Wallet developer Craig Raw and the Bitcoin Red Team. BTCPay officials noted that the sophistication of the attack suggests the potential use of AI-assisted code analysis, a growing threat vector that recently surfaced in similar exploits involving Coldcard hardware wallets.
Comments (0)
No comments yet. Be the first!