Late on Friday, attackers began draining bitcoin from Lightning nodes behind BTCPay Server, following a week where the Bitcoin Red Team's AI-assisted audits had already flagged thousands of bugs. The critical flaw was so severe that BTCPay told users to either update instantly or take their entire payment servers offline, according to CoinDesk.

Bitcoin Payments Panic as Lightning Server Credentials Leak
XOOMAR Intelligence
Analyst Take
BTCPay Server confirmed funds were stolen and urged anyone running LND, the dominant Lightning node software, to update to version 2.4.2 immediately. The vulnerability allowed unauthenticated remote access to LND's ".macaroon" credential files. Those files are the keys to the kingdom, granting software permission to control a Lightning node and move its funds.
"There is a critical vulnerability being actively exploited on BTCPay Server, which can result in the loss of funds."
Hardware wallet maker Foundation was among the first confirmed victims. CEO Zach Herbert said attackers drained the company's BTCPay Lightning node overnight, closing its channels and sweeping the funds. The pseudonymous operator of bitcoin publication Citadel21, hodlonaut, also reported a drained node, though noted it held little money. Both stressed their standard on-chain hot wallets were untouched.
BTCPay credited the disclosure to members of the Bitcoin Red Team, including Craig Raw, Rob Hamilton, Calle, and Evan Kaloudis. Founder Nicolas Dorier added a crucial detail, however, revealing the bug was not found by the Red Team's AI scans. It was discovered only after Sparrow Wallet developer Craig Raw lost funds and analyzed his logs.
XOOMAR Analysis: This is a flaw in credential persistence, not a protocol bug. The problem, according to related reports, was that old macaroon credentials remained valid even after previous software updates. Operators who had updated their BTCPay installations were still exposed because a manual credential refresh was required, a step easily missed. This creates a dangerous gap between "updated" and "secure" that attackers eagerly exploit.
Two High-Profile Draining Incidents Before the Public Alarm Sounded
The exploit's discovery timeline reveals a security process playing catch up with live attacks. Foundation's node was drained before BTCPay's public X alert went out. This suggests the attackers were already active and scanning for vulnerable servers, potentially for hours.
The attack vector was narrowly focused. It applied specifically to deployments using LND for Lightning, and funds held inside LND's own on-chain wallet could still be at risk because they sit under the compromised Lightning node. BTCPay's standard on-chain wallets, including hot wallets generated inside BTCPay, were not affected by the credential flaw itself.
This incident arrives during a brutal period for Bitcoin infrastructure security. It follows the Coldcard firmware flaw that led to a massive loss of funds, as we reported in Bitcoin 2011 Time Capsule Cashes Out Via FalconX Broker, and a wave of AI-assisted audits from the Bitcoin Red Team that flagged 85 critical bugs in what one developer called an "extremely bad" situation.
High-Profile Targets:
| Company/Entity | Impact Reported |
|---|---|
| Foundation (Hardware Wallet Maker) | Lightning node drained, channels force-closed. |
| Citadel21 (Bitcoin Publication) | Lightning node swept, minimal funds lost. |
The choice of targets is notable. Hodlonaut speculated the attacks felt targeted at "the very heart" of the bitcoin social layer, hitting "enthusiast/hardcore tools, used by the people who live and bleed Bitcoin."
The Urgent Patch and the Lingering Credential Problem
BTCPay's response was blunt and urgent. The project released version 2.4.2 on August 7, 2026, with release notes headlined by a stark warning. It also required an update to its NBXplorer backend to version 2.6.10. The fix reportedly makes nine controller methods across five files non-routable, closing off endpoints that were accidentally reachable.
Crucially, the patch alone may not be enough. BTCPay has advised users to refresh macaroons and the macaroons.db file after applying the update. This manual step is critical because stolen credentials can still grant access to a node even after the software vulnerability is patched. If old macaroons are not invalidated, the attacker's stolen keys remain valid.
For operators, the immediate checklist is severe:
- Update BTCPay Server to 2.4.2 and NBXplorer to 2.6.10 immediately.
- Refresh all macaroon credentials and related authentication strings.
- Move funds if they are stored in a hot wallet generated by BTCPay's LND integration.
- If you cannot update instantly, shut down the server completely.
The self-hosted nature of BTCPay means there is no central operator to push a fix. Every merchant, exchange, or individual running a node must execute these steps themselves. This decentralization is a core strength for censorship resistance, but as this incident shows, it is a severe weakness for rapid, uniform security response.
XOOMAR Inference: The fallout here extends beyond patching. It forces a reckoning with the self-hosting paradox. Foundation builds hardware wallets designed for maximum user control, yet its own self-hosted payment infrastructure was compromised. Maintaining airtight security across every layer of a personal stack is notoriously demanding, even for experts. This exploit underscores that the weakest link for many Bitcoin users is not the protocol, but the administrative complexity of the tools built on top of it.
A full technical postmortem from BTCPay and the Bitcoin Red Team is pending. Until it arrives, the broader ecosystem will be scrutinizing every integration between wallet software and node implementations, questioning what other "sneaky" credential vulnerabilities might be lurking, untouched by automated scans. The race is on between those audits and the next set of live exploits.
Disclaimer: This XOOMAR analysis is for informational and educational purposes only. It is not financial, investment, legal, tax, or professional advice. It does not provide buy, sell, hold, price-target, portfolio, or personalized recommendations. Verify information independently and consult qualified professionals before making decisions.
Impact Analysis
- Merchants relying on Lightning for fast payments lost funds and faced urgent, disruptive server shutdowns.
- It exposes a critical software dependency risk in the broader Bitcoin ecosystem, where a flaw in a single client impacts many services.
- The incident casts doubt on automated security tools and highlights that human-led audits remain essential.
Sources
Disclaimer: Content on XOOMAR is produced using AI-assisted research, drafting, and verification workflows and is intended for informational and educational purposes only. It does not constitute financial, investment, legal, tax, medical, or professional advice of any kind. All analysis reflects available information at the time of publication and may not be current. Verify information independently and consult qualified professionals before making decisions. Editorial policy
Written by
XOOMAR Insights Team
Research and Editorial Desk
The XOOMAR Insights Team pairs automated research with human editorial judgment. We track hundreds of sources across technology, fintech, trading, SaaS, and cybersecurity, cross-check the facts, and explain what happened, why it matters, and what to watch next. We do not just rewrite headlines. Every article is fact-checked and scored for reliability before it goes live, and we link back to the original sources so you can verify anything yourself.
Explore More Topics
Related Articles
FintechBhutan Bets Bitcoin Treasury on City Funding Gamble
Bhutan pivoted from holding its national bitcoin reserve to hiring a manager to actively generate yield from it, aiming to fund the massive Gelephu Mindfulness
FintechTrump Media Bitcoin Move Traps Its BTC Stash in Debt
A $165 million BTC move left tagged Trump Media wallets almost equal to the amount pledged as loan collateral.
FintechOptions Sellers Smother Bitcoin Bull Run Hopes at $63K
Options sellers, AI capital and slow U.S. rules are capping Bitcoin's rally, STS Digital CEO Maxime Seiler says.
FintechBitcoin Treasury Companies Dump BTC as Debt Bites Hard
Bitcoin treasury firms are selling BTC to repay debt and pivot to AI, exposing a model built for rising coin prices.
FintechBitcoin's Clarity Act Surge Is a Political Mirage
OKX's Haider Rafique argues optimism around the Clarity Act is already priced into bitcoin, leaving only downside risk if the politically stalled bill fails.
CybersecurityIT Leaders Ditch Certifications for These Three Human Skills
Cybersecurity leaders are abandoning traditional hiring checklists, prioritizing innate curiosity and critical thinking over years of experience and certificati
CybersecurityN‑able Confirms Hackers Hijacked Customer Networks Using 'God Mode'
N‑able confirmed attackers used a critical 'God mode' flaw in its N‑central platform to breach customer networks, triggering two emergency hotfixes and a CISA u
CybersecuritySecurity Chaos Floods Apple Bug Bounties With AI Slop
A flood of AI-generated reports is overwhelming companies like Apple, forcing them to cap bug bounties as attacks swamp ports, banks, and infrastructure in a se
Future FictionThe Inherited Hours
An archivist tasked with curating the consciousness recordings of the newly deceased discovers a single 'ghost' who can perceive her presence, sparking a forbidden friendship that challenges the ethics of consent, legacy, and what it means to be company for the dead.
TechnologyMicrosoft Slaps Windows 11 with a Forced OneDrive Beta
Microsoft sabotages its own push to fix Windows 11 by automatically installing an unwanted, non-removable OneDrive Photos app, even on business PCs.
Don't miss the signal
Get our weekly roundup of the stories that matter across tech, fintech, and trading. No noise, just signal.
Free forever. No spam. Unsubscribe anytime.