BTCPay Hack Drains Lightning Nodes After Attackers Exploit Critical Flaw
Cryptocurrency trading is speculative and your capital is at risk when you trade. We may earn affiliate commissions from some of the products on this page - at no extra cost to you.

Highlights:
- BTCPay confirms attackers exploited a critical flaw affecting LND-based Lightning nodes.
- Version 2.4.2 patches the vulnerability and regenerates exposed LND macaroons.
- Foundation and Citadel21 also publicly reported Lightning node losses linked to the breach.
BTCPay Server confirmed in an August 7 X post that attackers exploited a critical flaw affecting Lightning Network nodes running through its software. The breach exposed LND credential files, giving intruders access to funds held on compromised nodes across vulnerable systems. Developers released version 2.4.2 after confirming thefts and urged operators to install the update immediately. Users who cannot patch quickly should shut down affected servers until they can secure them.
The project credited Bitcoin Red Team researchers with reporting the issue before public disclosure. Developers have not yet disclosed total losses, affected merchant numbers, or the exact start of the attacks.
The vulnerability allowed an unauthenticated remote attacker to obtain LND .macaroon files from vulnerable installations. Those files control permissions for Lightning nodes and can grant broad access when attackers obtain them. With that access, intruders could move funds, close payment channels, and take control of connected node activity. Developers said the flaw affects installations using any version before 2.4.2.
There is a critical vulnerability being actively exploited on BTCPay Server, which can result in the loss of funds.
Please update your BTCPayServer to 2.4.2 by going to Admin Dashboard -> Server -> Maintenance -> Update & verify the 2.4.2 version string in the footer.
If you…
— BTCPay Server (@BtcpayServer) August 7, 2026
BTCPay Patch Targets Exposed LND Credentials
The new release closes the security gap and regenerates LND macaroons during the upgrade process. Operators should also update LND to version 0.21.1 through the server maintenance dashboard. Moreover, administrators should replace exposed credentials and recreate the macaroons.db file where required. The project also advised users to refresh authentication strings for other Lightning backends.
Meanwhile, affected operators should review their nodes for unusual peers, unexplained payments, or unexpected channel closures. Developers also advised users with generated hot on-chain wallets to move funds and recreate those wallets. However, the confirmed exploit centers on LND credentials and Lightning node access. The project has not published technical exploit details while users complete security updates.
The project credited security contributors for helping investigate the incident and coordinate disclosure. However, founder Nicolas Dorier said the exploited bug did not appear in the Bitcoin Red Team’s AI-generated report. He said developer Craig Raw helped identify the problem after an affected instance exposed useful logs.
This bug is the worst since BTCPay was created. I am devastated about the loss incurred.@craigraw saved a lot of people by pointing us to the right direction after being drained, so we could fix and communicate as fast as we could. Even AI scans didn't find the issue. https://t.co/GJBPyy0UFz
— Nicolas Dorier (@NicolasDorier) August 7, 2026
Meanwhile, at least two organizations have publicly reported losses linked to the attack. Foundation chief executive Zach Herbert said attackers drained the company’s Lightning node during the night. He added that the company’s on-chain wallet did not lose funds. Bitcoin publication Citadel21 also confirmed a node breach, although it said the affected balance was small.
Recent Bitcoin Security Incidents Raise Attention
Bitcoin Red Team members reported the BTCPay vulnerability to developers before wider disclosure. The volunteer security group recently reviewed hundreds of Bitcoin open-source projects using AI-assisted tools and manual analysis. Its broader review identified 4,962 potential issues across 390 projects during roughly 30 hours. Researchers privately shared serious findings with developers before releasing public details.
Notably, the audit does not show that attackers used artificial intelligence during the server exploit. The project has not disclosed the attackers’ methods beyond the exposed credential path. It also has not published a complete count of compromised servers. Developers plan a fuller incident review after more operators finish applying the patch.
The incident also follows separate reports involving Coldcard hardware wallet users. On July 31, Bitcoin hardware wallet maker Coinkite said about 500 users lost 594.48 BTC after a seed-generation flaw exposed some wallets. On August 4, Galaxy Research confirmed Coldcard exploit losses at 1,596 BTC, worth over $100 million. The firm expects the total to rise as teams verify additional cases.
Meanwhile, Bitcoin network activity has jumped during the Coldcard security scare. Santiment reported 2.27 million new wallets over the period, its highest twelve-month reading. It also counted about 751,000 active wallets, the strongest level in roughly ten months.
Best Crypto Exchange
- Over 90 top cryptos to trade
- Regulated by top-tier entities
- User-friendly trading app
- 30+ million users
eToro is a multi-asset investment platform. The value of your investments may go up or down. Your capital is at risk. Don’t invest unless you’re prepared to lose all the money you invest. This is a high-risk investment, and you should not expect to be protected if something goes wrong.







