BTCPay Server Fixes critical LND credential vulnerabilities to prevent lightning wallets from being stolen
2026-08-12 00:45:29
According to CoinMeta, BTCPay Server has released version 2.4.2, which fixes a critical vulnerability that allowed unauthorized remote access to LND credential files. Attackers exploited this vulnerability to steal merchants' Lightning wallets. The project's release note describes a serious vulnerability involving macaroon files, which are used to manage access permissions for LND. BTCPay supporters also offer a recovery bonus equal to 10% of the returned funds, with a cap of 3 BTC. At current prices, the maximum reward is approximately $190,000. This incident is not a Bitcoin protocol vulnerability but rather a server-side security issue affecting certain servers that use LND and BTCPay Server settings. Affected merchants should update their systems as soon as possible to ensure security.
Bullish 0
Bearish 0
Source:Internet
This content is for market information only and does not constitute investment advice.