Monedas38449
Capitalización$ 2.27T-1.16%
Volumen Spot 24h$ 22.32B-0.06%
DominanciaBTC56.61%-0.31%ETH9.97%-1.15%
Gas ETH0.07 Gwei
Cryptorank
/

Bitcoin Payment Tool BTCPay Urges Update After Attackers Steal Funds

Bitcoin Payment Tool BTCPay Urges Update After Attackers Steal Funds

Compartir:

AI Vista

A critical BTCPay Server vulnerability allowed attackers to retrieve LND .macaroon credentials on versions prior to 2.4.2 and steal funds from Lightning nodes, prompting an urgent patch to BTCPay Server 2.4.2 and LND 0.21.1 which regenerates macaroons or requires taking servers offline. The incident, separate from the Bitcoin protocol, follows the Coldcard exploit that confirmed 1,719 BTC (~$111M) stolen with total losses likely above $130M, highlighting widening crypto security and self-custody risks.

Bajista

Mercados de predicciones

Vea en qué se centran los traders

Ver análisis →
Prediction Banner

In Brief

  • A BTCPay Server flaw exposed LND credentials, letting attackers steal user funds.
  • Version 2.4.2 patches the bug and regenerates macaroons.
  • The exploit lands after the Coldcard hack losses topped $130 million.

BTCPay Server confirmed that attackers exploited a critical flaw to steal funds from users running any version prior to 2.4.2 and urged operators to update immediately.

The self-hosted Bitcoin payment processor released version 2.4.2 to close the vulnerability. The issue allowed an unauthenticated remote attacker to obtain .macaroon credential files for LND, a common Lightning Network implementation.

What BTCPay Server Users Must Do

The stolen credentials could hand an attacker full control of an LND node. From there, the attacker could move funds directly out of the node.

“We have confirmed that attackers exploited this vulnerability. Users were affected and funds were stolen. We are not publishing technical details yet because operators still need time to update,” the team said.

Follow us on X to get the latest news as it happens

The risk applies specifically to deployments using LND. Other Lightning setups and non-Lightning users face no credential exposure, though the project still urged them to update. BTCPay Server’s own on-chain and hot wallets remain unaffected.

Operators who use LND should update to version 2.4.2 and LND 0.21.1 through the maintenance dashboard. The update regenerates macaroons automatically. Those unable to patch immediately were told to take their servers offline.

The project also advised LND users to review node activity for unfamiliar peers, unexpected channel closures, and payments they did not make.

A Second Blow to Bitcoin Self-Custody

The disclosure follows another major security incident. Galaxy Research confirmed on Friday that 1,719 Bitcoin (BTC), worth roughly $111 million, has been stolen from Coldcard users so far. The firm expects total losses to exceed $130 million once outstanding cases are verified.

Neither incident touched the Bitcoin protocol itself. Both instead exposed weaknesses in the tools built around it. 

Subscribe to our YouTube channel to watch leaders and journalists provide expert insights

Read the article at BeInCrypto
Leer el artículo en BeInCrypto

En esta nota

Criptomonedas

$ 64.13K

-1.45%

$ 0.000871

-7.21%

Fondos

Mercados de predicciones

Vea en qué se centran los traders

Ver análisis →
Prediction Banner

Compartir:

En esta nota

Criptomonedas

$ 64.13K

-1.45%

$ 0.000871

-7.21%

Fondos

Mercados de predicciones

Vea en qué se centran los traders

Ver análisis →
Prediction Banner

Compartir:

Leer más

Bitcoin Knots Says the Network Is Under Attack, Ripple’s Ex-CTO Calls it Nonsense

Bitcoin Knots Says the Network Is Under Attack, Ripple’s Ex-CTO Calls it Nonsense

In Brief Bitcoin Knots says the network is under attack and blocks have slowed. Chai...
Trump Media Books $190 Million Paper Loss Across Crypto and Equities

Trump Media Books $190 Million Paper Loss Across Crypto and Equities

In Brief Trump Media posted a $238.1 million net loss in the second quarter. Unreali...