BTCPay Server patches critical Lightning vulnerability, awards 0.42 BTC
In brief
- BTCPay Server patched critical vulnerability in Lightning integration exposing LND node credentials
- Version 2.4.2 released; project awarded 0.42 BTC to responsible security researchers
- Attackers stole funds before patch; on-chain Bitcoin wallets remained unaffected
- Users must update immediately; BTCPay launched bounty for stolen funds recovery
The Vulnerability
BTCPay Server disclosed a critical vulnerability affecting deployments running LND Lightning nodes. The flaw exposed .macaroon credential files to unauthenticated remote access, allowing attackers to hijack Lightning nodes and drain funds from active payment channels.
Confirmed reports indicate that thefts were already in motion before the patch arrived. On-chain Bitcoin wallets were not affected — the vulnerability was isolated to the Lightning integration layer.
Response and Recovery
The project patched the issue in version 2.4.2. Credit for the responsible disclosure goes to Craig Raw, the developer behind Sparrow Wallet, along with Bitcoin Red Team members Rob Hamilton, Calle, and Evan Kaloudis.
BTCPay Server donated 0.42 BTC to the security researchers who flagged the flaw. The project also announced a bounty program targeting the recovery of stolen funds, though the total amount stolen has not been publicly disclosed.
Users running vulnerable deployments must take immediate action. The advisory is straightforward: update to BTCPay Server v2.4.2 and LND v0.21.1 immediately. If macaroon files were compromised before patching, updating software alone won't undo the damage — affected operators need to rotate credentials and potentially close and reopen channels with fresh keys.
This incident reflects BTCPay Server's track record on security. Back in 2022, the project issued a $5,000 bounty for a separate vulnerability disclosure, signaling a commitment to responsible disclosure practices within the Bitcoin ecosystem.


