News

BTCPay Restricts Remote LND Access After Critical Credential Theft

BTCPay Server has restricted public remote access to LND after attackers stole credentials and funds. Version 2.4.2 rotates macaroons and tightens security. Operators must update quickly and inspect their Lightning nodes for compromise or unexpected losses.

Written By : Yusuf Islam
Reviewed By : Manisha Sharma

BTCPay Server restricted public remote access to Lightning Network nodes using LND after attackers exploited a critical flaw to steal credentials and move funds. The project said every version before 2.4.2, including release candidates, faces exposure. 

Attackers obtained LND ‘macaroon’ files, which can authorize control over a node and its funds. BTCPay confirmed user losses but has not disclosed the total stolen amount or the number of affected operators.

BTCPay Temporarily Cuts Public LND Access

BTCPay Server 2.4.2 removes public access to the LND API on Docker deployments while maintainers work on a safer remote-access setup. As a result, external wallets such as Zeus cannot connect through a BTCPay Server domain or Tor onion address.

Lightning payments can continue during the restriction. BTCPay said it plans to restore remote access once it considers the configuration safe for operators. The project is also withholding full technical details while users complete upgrades and review their nodes.

The update also moves standard deployments to LND 0.21.1 and automatically regenerates macaroon credentials. Operators should review payments, channel closures, peers, and balance changes for signs of unauthorized activity. Unexpected movements could indicate that attackers gained access before the security update.

Operators with Custom Exposure Need Extra Action

BTCPay warned that its update does not close LND access routes that operators manage outside the platform. Those routes can include reverse proxies, separate Tor services, forwarded ports, or other custom connections.

Operators using those setups must rotate credentials separately because the BTCPay update cannot secure independently managed routes. BTCPay also advised anyone unable to update immediately to take affected LND deployments offline.

How many operators still face risk through independently managed LND access routes? BTCPay has not disclosed the number of compromised operators or the total amount attackers stole. The project has only confirmed that real users lost funds during the incident.

Also Read: Crypto Wallets Expand into Trading Payments and Yield Platforms

Security Update Also Tightens Greenfield API Controls

Version 2.4.2 also strengthens Greenfield API security. The release fixes a TOTP two-factor authentication bypass involving Basic authentication and changes the default behavior for newly created accounts.

The update now disables Basic authentication by default five minutes after account creation unless users choose to enable it again. BTCPay has not confirmed whether attackers used that path to obtain LND credentials. Therefore, the exact attack route remains undisclosed.

At least two operators reported losses publicly. Foundation CEO Zach Herbert said attackers drained the company’s Lightning node, closed its channels, and swept funds while leaving its BTCPay on-chain hot wallet untouched.

Bitcoin publication Citadel21 also said attackers swept its Lightning node. Neither operator disclosed the amount lost. Those public reports align with BTCPay’s confirmation that the vulnerability caused actual thefts.

BTCPay said standard on-chain wallets, including hot wallets, do not face the LND credential issue. Funds inside LND’s own on-chain wallet can still face risk because compromised macaroon keys may authorize node control.

The project plans to publish a fuller postmortem after more operators complete upgrades and security steps. Until then, it continues to limit technical disclosure while operators secure affected deployments.

A Brief Roundup

BTCPay Server restricted public LND access after attackers stole macaroon credentials and moved funds. Version 2.4.2 rotates credentials and tightens API security. Operators should update, inspect node activity, and rotate credentials on any independently managed LND access routes. The project plans a fuller postmortem after operators complete upgrades.

Join our WhatsApp Channel to get the latest news, exclusives and videos on WhatsApp

BlockDAG's 10 Billion Staked & 374,400 Holders Signal Growing Conviction as INJ Eyes $7 & VET Price Builds Base

Dogecoin Price Prediction for August 2026

Stellar and Litecoin Drift Sideways in August as INVEST Network Pairs a $0.00043 Presale With a Dual-Yield Mining Strategy

Brazil Sets 24-Hour Crypto Transfer Delays Starting January 2027

Crypto News Today: XRP Transactions Decline, HYPE Revenue Falls, and TUT Witnessed Heavy Liquidation