FacebookTwitterLinkedInTelegramCopy LinkEmail
Crime

Bitcoin Payment Processor Confirms Funds Stolen – Who Is Actually at Risk?

Bitcoin Payment Processor Confirms Funds Stolen – Who Is Actually at Risk?

BTCPay Server has confirmed that attackers exploited a critical vulnerability and stole funds from affected users.

The risk is specific to vulnerable BTCPay installations using LND rather than BTCPay users broadly. Because exposed node credentials can provide significant control, affected operators should treat the incident as an active security issue.

Key Takeaways

  • BTCPay confirmed the flaw was exploited.
  • LND users below version 2.4.2 must update.
  • Other Lightning setups face no specific exposure.
  • Users should inspect nodes after updating.

What Actually Happened?

The attackers did not need to break Bitcoin’s cryptography or obtain a seed phrase.

BTCPay says the vulnerability could allow an unauthenticated remote attacker to obtain LND .macaroon files. These files carry permissions used to interact with an LND node. If stolen credentials provide enough authority, they can allow someone else to perform actions on that node, including actions involving funds.

The attacks reviewed by BTCPay targeted files with the .macaroon extension. The project has confirmed that users were affected and funds were stolen, but it is withholding full technical details while operators have time to patch their systems.

Who Is Actually Affected?

Users running LND on a BTCPay Server version earlier than 2.4.2, including 2.4.2 release candidates, should treat their installation as affected and update immediately.

BTCPay says other Lightning implementations are not exposed to this particular LND credential issue. The same applies to installations that do not use Lightning, although the project still strongly recommends updating older BTCPay Server versions.

BTCPay’s own on-chain wallets, including hot wallets, were not affected by the vulnerability identified in the advisory. LND’s own on-chain wallet is different: those funds form part of the affected LND node and may still be at risk if control of the node was compromised.

So the incident is serious, but its confirmed scope is more specific than a compromise of every wallet running through BTCPay Server.

What Should BTCPay Users Do Now?

Affected LND users should update to BTCPay Server 2.4.2, which also upgrades LND to version 0.21.1. Anyone unable to update immediately is advised to take the server offline until they can.

Once patched, users should review what happened on the node before the update.

BTCPay recommends checking for payments they did not make, unexpected channel closures, unfamiliar peers and differences between expected balances and what the node currently shows.

Credentials may need attention as well. The update regenerates LND macaroons, but users who expose the node through infrastructure they manage separately, such as a reverse proxy, forwarded port or Tor service, should review those access routes and rotate credentials where necessary.

The reason is straightforward: installing the patch closes the known vulnerability, but it cannot determine whether credentials were copied while the server was still exposed.

BTCPay has published additional precautions for different configurations following the incident. Users with more complex setups should check the project’s latest instructions rather than treating the software update as the end of the security review.

Bitcoin Custody Debate

The disclosure comes during an awkward week for Bitcoin holders already reconsidering how they secure their coins.

A separate Coldcard incident recently revived questions about the responsibilities that come with holding Bitcoin directly. We explored that issue in our analysis of the Coldcard flaw and the renewed Bitcoin wallet-versus-ETF custody debate.

The two incidents involve different security problems. Coldcard concerns a hardware-wallet environment. BTCPay’s vulnerability involved credentials associated with Lightning infrastructure. Neither indicates that Bitcoin itself was compromised.

Their proximity does, however, highlight how many components can matter once users take direct responsibility for their coins.

A seed phrase may be perfectly safe while software or server credentials create another route to funds. For people running their own infrastructure, hardware security is only part of the job; network exposure, access permissions and software maintenance matter as well.

Some holders may respond by moving more of that responsibility to a custodian or gaining Bitcoin exposure through an ETF. That removes many of the technical tasks faced by an individual operator, but leaves the assets dependent on third-party custody and the protections surrounding it.

After two very different security incidents in the same week, the practical question is less about finding a custody method with no risk and more about understanding exactly where control sits.

Which device, credential or service can move the funds? Who controls it? And if something is exposed, how quickly can that access be replaced or revoked?

For affected BTCPay users, the immediate priorities are simpler: update the server, inspect the LND node and deal with any credentials that may have been exposed.


  • Methodology: This article is based on BTCPay Server’s security advisory and subsequent public guidance regarding the vulnerability, affected LND deployments, version 2.4.2 and recommended mitigation steps. Technical details have been simplified to explain the practical impact for users.
  • Disclaimer: This article is provided for informational and educational purposes only. Users operating BTCPay Server or LND should follow the project’s latest official security instructions for their specific setup.
Author
Kosta Gushterov, journalist in Coindoo.com

Reporter at Coindoo

Kosta has reported on cryptocurrency markets and blockchain infrastructure since 2020, bringing over six years of hands-on experience in the crypto industry built through daily tracking of markets, trends, and emerging blockchain developments. Specializing in Bitcoin on-chain analysis, institutional ETF flows, and digital asset price action, his work at Coindoo has been cited by other news agencies and consistently covers market developments with a focus on data-driven reporting across Bitcoin, Ethereum, Solana, and XRP. Over the years, Kosta has contributed to multiple crypto media outlets in different regions, authoring over 6,000 articles across the sector. His reporting spans cryptocurrency markets and the broader fintech industry, tracking not only price action but also the technological and regulatory forces shaping the ecosystem. To support his analysis, Kosta actively leverages on-chain data and metrics from leading platforms such as Santiment, Glassnode, and CryptoQuant, enabling deeper, evidence-based market insights. He believes in the power of transparency and the data that underpins the blockchain ecosystem. His academic background in Marketing Management from Denmark further complements his analytical approach, adding a strong understanding of communication strategy and content positioning to his work.

Learn more about crypto and blockchain technology.

Glossary