A critical credential-file vulnerability in BTCPay Server is enabling active exploitation of merchant Lightning Network nodes, with attacks confirmed since Friday night and a v2.4.2 patch now available for immediate deployment.
- The BTCPay exploit targets improperly secured LND credential files, allowing remote fund drainage from merchant nodes.
- Active exploitation of the LND drain vector began Friday night, with an unknown number of merchants affected.
- BTCPay Server v2.4.2 patch closes the exposure; operators without it remain at full risk.
Lead
A critical security flaw in BTCPay Server, the widely deployed open-source Bitcoin payment processor, is allowing attackers to drain funds from merchants' Lightning Network Daemon (LND) nodes by accessing exposed credential files. Exploitation began Friday night, prompting an emergency release of BTCPay Server v2.4.2, which patches the vulnerability. Merchants running any prior version who have not yet upgraded face complete loss of funds held in active Lightning channels.
What Happened
The vulnerability stems from improperly protected LND credential files — specifically `admin.macaroon` and `tls.cert` — that BTCPay Server instances stored or served in locations accessible without authentication under certain deployment configurations. Possession of these files grants full administrative control over an LND node, including the ability to initiate outbound payments and close channels to attacker-controlled addresses.
The BTCPay exploit does not require physical access to server hardware. Attackers scanning for exposed endpoints can retrieve credential files over standard HTTP, then interact directly with the target node's gRPC or REST API to execute the LND drain. The attack leaves minimal forensic footprint during execution, complicating incident response.
Exploitation Timeline
Scanning activity consistent with automated credential-file harvesting was first detected Friday evening. By Saturday morning, reports from merchants in Europe and North America confirmed active fund loss. The attack surface is bounded to operators running self-hosted BTCPay deployments with LND as the Lightning backend; merchants using hosted services or alternative node implementations — including Core Lightning — are unaffected by this specific vector.
The v2.4.2 Patch
The v2.4.2 patch restricts file-system permissions on LND credential materials, removes unauthenticated access paths introduced in an earlier configuration refactor, and adds a startup integrity check that flags insecure credential exposure before the server accepts payment requests. The BTCPay maintainer team released the update on an accelerated schedule, bypassing the standard changelog review cycle given the severity of the active exploit.
Operators are advised to upgrade immediately, rotate all LND macaroons post-upgrade, and audit channel balances against pre-incident records to quantify potential losses.
Strategic Context
BTCPay Server processes payments for tens of thousands of merchants globally, ranging from independent retailers to mid-market e-commerce operators. The Lightning Network's non-custodial architecture — a core selling point over third-party payment processors — also means that losses from an LND drain are generally unrecoverable absent attacker cooperation. There is no central authority to reverse channel-closure transactions once confirmed on-chain.This incident highlights a persistent tension in the self-custody payments stack: operational security requirements that are routine for enterprise infrastructure teams remain a meaningful burden for smaller merchants who chose BTCPay Server precisely to avoid dependence on centralized intermediaries.
Outlook
Immediate remediation via the v2.4.2 patch is the sole near-term defensive action available to exposed operators. The broader BTCPay development community is expected to conduct a post-incident review of credential-handling practices across all supported Lightning backends. Merchants who suffered losses face an uninsured gap; the episode will likely accelerate demand for managed Lightning node services that abstract credential security away from end-operators, even at the cost of partial custody.
Mentioned tickers: none




