BTCPay Server Patches Critical LND Credential Bug After Lightning Wallet Drain
BTCPay Server released version 2.4.2 to fix a critical server-side vulnerability in setups using LND. The bug could expose LND credential files, including .macaroon files, which can grant sensitive permissions to a Lightning node. Attackers used the flaw to drain some merchant Lightning wallets. This was not a Bitcoin protocol or on-chain wallet failure. It affected BTCPay Server infrastructure and LND configuration, so operators need to patch, review credential storage, and check exposed services. Supporters also launched a recovery bounty offering 10% of returned funds, capped at 3 BTC, to encourage fund recovery or disclosure. The incident highlights that self-hosted Bitcoin payment systems require ongoing security updates, careful permissions, and strong operational hygiene.
