BTCPay Server told users on Friday that attackers are actively exploiting a critical vulnerability and urged an immediate update to version 2.4.2 or a shutdown. Hardware wallet maker Foundation and the Bitcoin zine Citadel21 both said their Lightning nodes were swept, in some cases before the warning went out, and the project says the exploited flaw is not the one already disclosed in its changelog.
BTCPay Server, the self-hosted Bitcoin payment processor, warned users on Friday that attackers are actively exploiting a critical vulnerability that can result in the loss of funds. The project urged administrators to install version 2.4.2 and confirm the update in the server footer, or turn their servers off until they could patch.
Nodes swept before the alert went out
Attackers had already drained Lightning nodes by the time the warning circulated, including one run by hardware wallet maker Foundation. According to The Defiant: "Our Foundation node was drained overnight by attackers", said Foundation co-founder and chief executive Zach Herbert, who added that only the Lightning Network node was hit and the hot wallet was untouched.
The pseudonymous commentator hodlonaut said Citadel21's Lightning node was swept too, though not much money was lost there. He added that the caution stemmed from precautions tied to a possible BIP-110 activation.
Not the bug in the changelog
BTCPay Server credited members of the Bitcoin Red Team with reporting the vulnerability, but the project has not disclosed how the flaw works, when the attacks began, or how many servers were compromised. Founder Nicolas Dorier also said the bug being exploited is not the two-factor authentication bypass already disclosed in the 2.4.2 changelog, which was fixed on Aug. 4.
Refresh your macaroons
The project also told users to replace credentials known as macaroons, recreate the macaroons.db file, and refresh authentication strings for other Lightning backends; anyone who generated a hot wallet inside BTCPay should move those funds and recreate it. That step matters because stolen credentials survive a software update — an attacker who copied them before the patch keeps node access until the files are destroyed and reissued.
The incident follows a rough stretch for self-hosted bitcoin infrastructure. A Coldcard firmware flaw has already left a balance of more than 1,700 BTC stolen, according to Galaxy Research.
Swap provider Boltz separately halted its service on Aug. 3, citing AI-assisted attacks. Bitcoin traded near $64,800 on Friday afternoon, up 0.7% over 24 hours and 2.6% on the week, showing no reaction to the disclosure.
Sources:
Trading involves risk.