XOOMAR
Close-up of Bitcoin trading app on smartphone showing market trends and digital coins.
FintechAugust 8, 2026· 5 min read· By XOOMAR Insights Team

Bitcoin Payments Panic as Lightning Server Credentials Leak

Share
Updated on August 8, 2026

Late on Friday, attackers began draining bitcoin from Lightning nodes behind BTCPay Server, following a week where the Bitcoin Red Team's AI-assisted audits had already flagged thousands of bugs. The critical flaw was so severe that BTCPay told users to either update instantly or take their entire payment servers offline, according to CoinDesk.

XOOMAR Intelligence

Analyst Take

56/ 100
Moderate
4 sources analyzedLow confidenceTrend10Freshness96Source Trust88Factual Grounding85Signal Cluster20

BTCPay Server confirmed funds were stolen and urged anyone running LND, the dominant Lightning node software, to update to version 2.4.2 immediately. The vulnerability allowed unauthenticated remote access to LND's ".macaroon" credential files. Those files are the keys to the kingdom, granting software permission to control a Lightning node and move its funds.

"There is a critical vulnerability being actively exploited on BTCPay Server, which can result in the loss of funds."

Hardware wallet maker Foundation was among the first confirmed victims. CEO Zach Herbert said attackers drained the company's BTCPay Lightning node overnight, closing its channels and sweeping the funds. The pseudonymous operator of bitcoin publication Citadel21, hodlonaut, also reported a drained node, though noted it held little money. Both stressed their standard on-chain hot wallets were untouched.

BTCPay credited the disclosure to members of the Bitcoin Red Team, including Craig Raw, Rob Hamilton, Calle, and Evan Kaloudis. Founder Nicolas Dorier added a crucial detail, however, revealing the bug was not found by the Red Team's AI scans. It was discovered only after Sparrow Wallet developer Craig Raw lost funds and analyzed his logs.

XOOMAR Analysis: This is a flaw in credential persistence, not a protocol bug. The problem, according to related reports, was that old macaroon credentials remained valid even after previous software updates. Operators who had updated their BTCPay installations were still exposed because a manual credential refresh was required, a step easily missed. This creates a dangerous gap between "updated" and "secure" that attackers eagerly exploit.


Two High-Profile Draining Incidents Before the Public Alarm Sounded

The exploit's discovery timeline reveals a security process playing catch up with live attacks. Foundation's node was drained before BTCPay's public X alert went out. This suggests the attackers were already active and scanning for vulnerable servers, potentially for hours.

The attack vector was narrowly focused. It applied specifically to deployments using LND for Lightning, and funds held inside LND's own on-chain wallet could still be at risk because they sit under the compromised Lightning node. BTCPay's standard on-chain wallets, including hot wallets generated inside BTCPay, were not affected by the credential flaw itself.

This incident arrives during a brutal period for Bitcoin infrastructure security. It follows the Coldcard firmware flaw that led to a massive loss of funds, as we reported in Bitcoin 2011 Time Capsule Cashes Out Via FalconX Broker, and a wave of AI-assisted audits from the Bitcoin Red Team that flagged 85 critical bugs in what one developer called an "extremely bad" situation.

High-Profile Targets:

Company/Entity Impact Reported
Foundation (Hardware Wallet Maker) Lightning node drained, channels force-closed.
Citadel21 (Bitcoin Publication) Lightning node swept, minimal funds lost.

The choice of targets is notable. Hodlonaut speculated the attacks felt targeted at "the very heart" of the bitcoin social layer, hitting "enthusiast/hardcore tools, used by the people who live and bleed Bitcoin."


The Urgent Patch and the Lingering Credential Problem

BTCPay's response was blunt and urgent. The project released version 2.4.2 on August 7, 2026, with release notes headlined by a stark warning. It also required an update to its NBXplorer backend to version 2.6.10. The fix reportedly makes nine controller methods across five files non-routable, closing off endpoints that were accidentally reachable.

Crucially, the patch alone may not be enough. BTCPay has advised users to refresh macaroons and the macaroons.db file after applying the update. This manual step is critical because stolen credentials can still grant access to a node even after the software vulnerability is patched. If old macaroons are not invalidated, the attacker's stolen keys remain valid.

For operators, the immediate checklist is severe:

  1. Update BTCPay Server to 2.4.2 and NBXplorer to 2.6.10 immediately.
  2. Refresh all macaroon credentials and related authentication strings.
  3. Move funds if they are stored in a hot wallet generated by BTCPay's LND integration.
  4. If you cannot update instantly, shut down the server completely.

The self-hosted nature of BTCPay means there is no central operator to push a fix. Every merchant, exchange, or individual running a node must execute these steps themselves. This decentralization is a core strength for censorship resistance, but as this incident shows, it is a severe weakness for rapid, uniform security response.

XOOMAR Inference: The fallout here extends beyond patching. It forces a reckoning with the self-hosting paradox. Foundation builds hardware wallets designed for maximum user control, yet its own self-hosted payment infrastructure was compromised. Maintaining airtight security across every layer of a personal stack is notoriously demanding, even for experts. This exploit underscores that the weakest link for many Bitcoin users is not the protocol, but the administrative complexity of the tools built on top of it.

A full technical postmortem from BTCPay and the Bitcoin Red Team is pending. Until it arrives, the broader ecosystem will be scrutinizing every integration between wallet software and node implementations, questioning what other "sneaky" credential vulnerabilities might be lurking, untouched by automated scans. The race is on between those audits and the next set of live exploits.


Disclaimer: This XOOMAR analysis is for informational and educational purposes only. It is not financial, investment, legal, tax, or professional advice. It does not provide buy, sell, hold, price-target, portfolio, or personalized recommendations. Verify information independently and consult qualified professionals before making decisions.

Impact Analysis

  • Merchants relying on Lightning for fast payments lost funds and faced urgent, disruptive server shutdowns.
  • It exposes a critical software dependency risk in the broader Bitcoin ecosystem, where a flaw in a single client impacts many services.
  • The incident casts doubt on automated security tools and highlights that human-led audits remain essential.

Disclaimer: Content on XOOMAR is produced using AI-assisted research, drafting, and verification workflows and is intended for informational and educational purposes only. It does not constitute financial, investment, legal, tax, medical, or professional advice of any kind. All analysis reflects available information at the time of publication and may not be current. Verify information independently and consult qualified professionals before making decisions. Editorial policy

XOOMAR

Written by

XOOMAR Insights Team

Research and Editorial Desk

The XOOMAR Insights Team pairs automated research with human editorial judgment. We track hundreds of sources across technology, fintech, trading, SaaS, and cybersecurity, cross-check the facts, and explain what happened, why it matters, and what to watch next. We do not just rewrite headlines. Every article is fact-checked and scored for reliability before it goes live, and we link back to the original sources so you can verify anything yourself.

Related Articles

Hand holding smartphone displaying digital wallet app interface, blurred monitor in background.Fintech

Bhutan Bets Bitcoin Treasury on City Funding Gamble

Bhutan pivoted from holding its national bitcoin reserve to hiring a manager to actively generate yield from it, aiming to fund the massive Gelephu Mindfulness

Aug 4, 20266 min
Digital vaults and crypto coins depict a major bitcoin collateral transfer in a fintech setting.Fintech

Trump Media Bitcoin Move Traps Its BTC Stash in Debt

A $165 million BTC move left tagged Trump Media wallets almost equal to the amount pledged as loan collateral.

Aug 3, 20267 min
Bitcoin-like coin halted by three symbolic barriers: trading, AI capital, and regulation.Fintech

Options Sellers Smother Bitcoin Bull Run Hopes at $63K

Options sellers, AI capital and slow U.S. rules are capping Bitcoin's rally, STS Digital CEO Maxime Seiler says.

Jul 31, 20268 min
Bitcoin treasury firm selling crypto assets, repaying debt, and pivoting toward AI amid market pressureFintech

Bitcoin Treasury Companies Dump BTC as Debt Bites Hard

Bitcoin treasury firms are selling BTC to repay debt and pivot to AI, exposing a model built for rising coin prices.

Jul 25, 20267 min
Man with a smartphone processing an online payment with a credit card. Soft light, modern lifestyle.Fintech

Bitcoin's Clarity Act Surge Is a Political Mirage

OKX's Haider Rafique argues optimism around the Clarity Act is already priced into bitcoin, leaving only downside risk if the politically stalled bill fails.

Aug 8, 20266 min
Wooden blocks spelling 'Cyber Security' on a wooden grid background.Cybersecurity

IT Leaders Ditch Certifications for These Three Human Skills

Cybersecurity leaders are abandoning traditional hiring checklists, prioritizing innate curiosity and critical thinking over years of experience and certificati

Aug 8, 20266 min
Futuristic workspace featuring a glowing computer screen with coding displayed, ideal for technology and programming concepts.Cybersecurity

N‑able Confirms Hackers Hijacked Customer Networks Using 'God Mode'

N‑able confirmed attackers used a critical 'God mode' flaw in its N‑central platform to breach customer networks, triggering two emergency hotfixes and a CISA u

Aug 8, 20266 min
Close-up view of a mouse cursor over digital security text on display.Cybersecurity

Security Chaos Floods Apple Bug Bounties With AI Slop

A flood of AI-generated reports is overwhelming companies like Apple, forcing them to cap bug bounties as attacks swamp ports, banks, and infrastructure in a se

Aug 8, 20267 min
Wide establishing shot of the Legacy Archive server hall, an immense, silent cathedral-like space with rows of softly pulsating light columns in a vast darkness. Clean, cool, architectural digital art, cinematic lighting with volumetric god rays, futuristFuture Fiction

The Inherited Hours

An archivist tasked with curating the consciousness recordings of the newly deceased discovers a single 'ghost' who can perceive her presence, sparking a forbidden friendship that challenges the ethics of consent, legacy, and what it means to be company for the dead.

Aug 8, 202613 min
A vintage CD-ROM drive showcasing a Windows 95 disc, reflecting retro technology.Technology

Microsoft Slaps Windows 11 with a Forced OneDrive Beta

Microsoft sabotages its own push to fix Windows 11 by automatically installing an unwanted, non-removable OneDrive Photos app, even on business PCs.

Aug 8, 20267 min

Don't miss the signal

Get our weekly roundup of the stories that matter across tech, fintech, and trading. No noise, just signal.

Free forever. No spam. Unsubscribe anytime.