BTCPay restricts remote Lightning access after attackers steal funds

Summary

BTCPay Server temporarily restricted public remote connections to Lightning nodes running LND after attackers used a critical flaw to steal macaroon credentials and move funds. The change affects external wallets connecting through BTCPay domains or Tor onion addresses on Docker setups; Lightning payments still work, and remote access will return when safe. Version 2.4.2 installs LND 0.21.1 and auto-rotates macaroons on standard installs. Operators are advised to check for unauthorized payments, unexpected channel closures, unknown peers, and balance mismatches. Sites exposing LND through their own proxies or services must rotate credentials separately. At least two operators reported drained Lightning nodes.