LIVE NEWS
  • Trump dangles $500 ACA refund checks, but legal basis is unclear
  • Guest post: How extreme heat is ‘creeping’ from summer into autumn and spring
  • Musk threatens to sue filmmaker Alex Gibney for defamation : NPR
  • 25 Years After 9/11, What Makes a Good Counterterrorism Strategy?
  • Twenty-five years after 9/11, strategic shocks mustn’t cloud strategic thinking
  • Infectious diseases will seed new ground as the planet warms — here’s where they’ll spread
  • India crypto takedowns target 15 platforms
  • NFL’s Rams and 49ers head to Australia in international expansion
Prime Reports
  • Home
  • Popular Now
  • Crypto
  • Cybersecurity
  • Economy
  • Geopolitics
  • Global Markets
  • Politics
  • See More
    • Artificial Intelligence
    • Climate Risks
    • Defense
    • Healthcare Innovation
    • Science
    • Technology
    • World
Prime Reports
  • Home
  • Popular Now
  • Crypto
  • Cybersecurity
  • Economy
  • Geopolitics
  • Global Markets
  • Politics
  • Artificial Intelligence
  • Climate Risks
  • Defense
  • Healthcare Innovation
  • Science
  • Technology
  • World
Home»Crypto»Lightning Nodes Drained As BTCPay Server Users Race To Patch
Crypto

Lightning Nodes Drained As BTCPay Server Users Race To Patch

primereportsBy primereportsAugust 9, 2026Updated:August 9, 2026No Comments6 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
Lightning Nodes Drained As BTCPay Server Users Race To Patch
Share
Facebook Twitter LinkedIn Pinterest Email


Hardware wallet maker Foundation and the Bitcoin zine Citadel21 both said their nodes were swept, in some cases hours before the project’s public alert. BTCPay says the flaw under attack is not the one disclosed in its changelog.

Attackers emptied Lightning nodes belonging to BTCPay Server users on Friday, including one run by hardware wallet maker Foundation, after the self-hosted bitcoin payment processor warned that a critical vulnerability was being actively exploited and told merchants to update to version 2.4.2 or shut their servers down.

Because BTCPay is self-hosted, there is no operator who can patch on behalf of its users. Every merchant, exchange and wallet running the software has to apply the fix on its own machine, and the thefts were already underway before the warning went out. The software sits behind bitcoin checkout for Namecheap, which ran $73 million in BTC revenue across 1.1 million transactions through BTCPay between May 2020 and October 2024, along with hundreds of smaller merchants and several wallet backends.

“There is a critical vulnerability being actively exploited on BTCPay Server, which can result in the loss of funds,” the project wrote at 11:51 a.m. ET. “If you are unable to update right away, turn off your BTCPay Server to prevent unauthorized access until you can update.” The post passed 550,000 views within five hours.

Founder Nicolas Dorier published release 2.4.2 the same morning with a one-line warning at the top: “This release contains fix of a critical vulnerability that is being actively exploited. You need to update as fast as you can.” The notes also tell integrators to upgrade NBXplorer, BTCPay’s wallet-tracking backend, to version 2.6.10.

Nodes Swept Overnight

Zach Herbert, chief executive of Foundation, the company behind the Passport hardware wallet, said his node was gone before he read the alert. “How many BTCPay lightning nodes were swept? Our Foundation node was drained overnight by attackers,” he wrote at 2:01 p.m. ET.

Herbert narrowed the damage an hour later: “This was just our BTCPay server that we use for payment processing, the hot wallet was untouched – only the lightning node was drained. All channels were closed and funds were swept.”

hodlonaut, the pseudonymous bitcoin commentator behind the zine Citadel21, reported the same pattern. “This is an ongoing attack on BTCPayserver users. Citadel21’s lightning node was just swept,” he wrote. “Fortunately there were not much funds there.”

At least one other operator described closed channels and drained funds in the replies to BTCPay’s warning. Neither Herbert nor hodlonaut disclosed amounts, and no one has published a tally of how many nodes were hit or how much bitcoin moved.

Found By Losing Money

The flaw surfaced because someone got robbed. Dorier credited Craig Raw, the developer of Sparrow Wallet, for working out what was happening.

“We got extremely lucky that a dev was impacted who could analyze the logs to understand what was going on,” Dorier wrote. “Somehow, this wasn’t found AI scans, but by him losing money. :(“

That cuts against the premise of the Bitcoin Red Team, the volunteer group that has spent this week running AI-assisted audits across bitcoin’s open-source stack and that BTCPay thanked for the disclosure. Dorier said the group’s scans missed it.

“The AI report we got from red team didn’t include this one,” he wrote. “But this bug was really sneaky, I am not surprised a simple scan didn’t find it, or thought it was low risk.”

Not The Bug In The Changelog

BTCPay has not said which flaw is being exploited, and Dorier ruled out the one authentication bug the changelog does disclose. After a user posted a Grok-generated explanation pinning the attack on that bug, Dorier replied: “This bug was found by the Red team, this isn’t the critical bug in question.”

The disclosed bug is a two-factor authentication bypass in Greenfield, BTCPay’s API, fixed on Aug. 4. The handler checked only for FIDO2 hardware keys before enforcing a second factor, so accounts protected by an authenticator app could be reached with an email and password alone and receive an unrestricted permission claim. The browser login screen enforced 2FA correctly the whole time.

Dorier followed that with a breaking change switching off Greenfield basic authentication five minutes after an account is created, reasoning that the scheme is almost never used and that turning it off shrinks the blast radius of related bugs. The release also rate-limits public invoice creation on payment requests, and a commit landed on release day marked nine controller methods across five files as non-routable, removing endpoints reachable over HTTP by accident.

A technical writeup is coming. “We are working with Bitcoin Red Team to fully process the details of vulnerability and will follow up with detail technical post shortly,” core contributor Uncle Rockstar wrote. Dorier, asked about holding details back, said: “I am wondering if it makes sense to wait… now that it is exploited in the wild.”

Refresh Your Macaroons

Patching alone does not close the incident. BTCPay told users to completely refresh macaroons and macaroons.db, the credential files that authorize access to an LND Lightning node, and to refresh authentication strings for other Lightning backends. Anyone who generated a hot on-chain wallet inside BTCPay should move those funds and recreate the wallet.

Kaloudis, whose ZEUS wallet runs on LND, put it more bluntly: “Don’t assume you’re safe after upgrading.”

Stolen macaroons survive a software update. An attacker who copied them before the patch keeps node access until the credentials are destroyed and reissued, which matches what the victims describe: channels force-closed and balances swept rather than the server itself compromised again.

Nine Days, Three Failures

The alert lands nine days into the worst stretch for bitcoin infrastructure security in years.

A 2021 Coldcard firmware bug that routed seed generation to a weak software randomizer has drained roughly $114 million in BTC since July 30 across more than 5,200 addresses, with victims describing the loss of life savings. On Aug. 3, the swap bridge Boltz halted its service indefinitely, saying “attackers now iterate faster than a team our size can find and patch.”

The Bitcoin Red Team formed in response to Coldcard. Calle, who helps run it, said on Aug. 5 that 16 researchers had filed 4,962 findings across 390 projects in 27.5 hours, including 85 critical and 635 high-severity issues.

Bitcoin traded near $64,800 on Friday afternoon, up 0.7% over 24 hours and 2.6% on the week, per CoinGecko, showing no reaction to the disclosure.

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleENS Labs Scales Back Treasury Proposal After Delegate Pushback
Next Article AAVE Price Prediction: Sell the Rips — $86 Is Closer Than the Bulls Will Admit
primereports
  • Website

Related Posts

Crypto

India crypto takedowns target 15 platforms

September 10, 2026
Crypto

CLARITY Act: Ripple CLO urges Senate to hear crypto holders

September 9, 2026
Crypto

U.S. Bank Moves USBDC Onchain in Cross-Border Pilot

September 9, 2026
Add A Comment
Leave A Reply Cancel Reply

Top Posts

Threat of further violence looms after Mexican cartel rampage

February 25, 2026116 Views

‘Two-sided risk’ Medicare Advantage plans improve patient outcomes

February 24, 202673 Views

An $18bn settlement – and Zuckerberg barely blinked. The tech titans must be stripped of their power, and soon | Jonathan Freedland

August 28, 202626 Views
Stay In Touch
  • Facebook
  • YouTube
  • TikTok
  • WhatsApp
  • Twitter
  • Instagram
Latest Reviews

Subscribe to Updates

Get the latest tech news from FooBar about tech, design and biz.

PrimeReports.org
Independent global news, analysis & insights.

PrimeReports.org brings you in-depth coverage of geopolitics, markets, technology and risk – with context that helps you understand what really matters.

Editorially independent · Opinions are those of the authors and not investment advice.
Facebook X (Twitter) LinkedIn YouTube
Key Sections
  • World
  • Crypto
  • Cybersecurity
  • Geopolitics
  • Artificial Intelligence
  • Popular Now
All Categories
  • Artificial Intelligence
  • Climate Risks
  • Crypto
  • Cybersecurity
  • Defense
  • Economy
  • Geopolitics
  • Global Markets
  • Healthcare Innovation
  • Politics
  • Popular Now
  • Science
  • Technology
  • World
  • About Us
  • Contact Us
  • Privacy Policy
  • Terms & Conditions
  • Disclaimer
  • Cookie Policy
  • DMCA / Copyright Notice
  • Editorial Policy

Sign up for Prime Reports Briefing – essential stories and analysis in your inbox.

By subscribing you agree to our Privacy Policy. You can opt out anytime.
Latest Stories
  • Trump dangles $500 ACA refund checks, but legal basis is unclear
  • Guest post: How extreme heat is ‘creeping’ from summer into autumn and spring
  • Musk threatens to sue filmmaker Alex Gibney for defamation : NPR
© 2026 PrimeReports.org. All rights reserved.
Privacy Terms Contact

Type above and press Enter to search. Press Esc to cancel.