Hackers have withdrawn funds from Lightning Network nodes through a vulnerability in BTCPay
8/10/2026, 08:03 AM • Евгения Слив

On the night of August 8, 2026, a series of cyber attacks were recorded, as a result of which attackers withdrew cryptocurrency funds from Lightning Network nodes operating through the BTCPay payment server. The project developers promptly confirmed the unauthorized access and issued an emergency warning, urging all users of the Lightning Network Daemon (LND) software to immediately update their systems to version 2.4.2 or temporarily disable the server before applying the patch. The technical essence of the vulnerability was incorrect processing of the .macaroon authentication files. These files are used by applications for secure access to the network node. Due to a software error, the attackers were able to remotely extract these files without going through the authorization procedure. The presence of a valid .macaroon file provided the attackers with full administrative control over the compromised node, which allowed them to initiate the closure of payment channels and withdraw accumulated funds to external addresses. The developers clarified that this vulnerability affects only configurations using LND, which is the most common software for managing Lightning Network nodes.
At the moment, the exact number of affected outlets and the total amount of funds withdrawn have not been disclosed, however, the BTCPay developers have promised to provide a detailed technical analysis of the incident in the coming days. It is important to note that standard bitcoin wallets integrated into the BTCPay ecosystem, including hot wallets, were not directly affected by this vulnerability. However, funds stored directly at LND addresses have been compromised, as these assets are managed through a compromised node. At least two organizations have already publicly announced their losses. Zach Herbert, CEO of Foundation, a hardware wallet manufacturer, confirmed that during the night, the attackers withdrew all available funds from the company's Lightning node deployed on the basis of BTCPay, while the organization's on-chain wallets remained intact. A similar fact of unauthorized access was confirmed by the specialized bitcoin publication Citadel21, whose representative noted that insignificant amounts were stored on the compromised server, which minimized direct financial damage to the publication.
The identification of this critical vulnerability was made possible by the initiative of the Bitcoin Red Team volunteer organization, which notified the BTCPay developers in advance of the problem in the code. In early August, this group began a large-scale and systematic audit of the code bases of various bitcoin projects with the active use of artificial intelligence algorithms, which allowed thousands of reports on potential attack vectors to be generated. This incident highlights the growing risks associated with self-deployment of nodes and management of the Lightning Network infrastructure without proper cybersecurity. The situation is also being considered against the background of recent major incidents in the industry: on the night of July 31, hackers exploited a vulnerability in the software of Coldcard hardware wallets, as a result of which about 500 users lost a total of 594.48 BTC, which at the current exchange rate is equivalent to about 38.2 million dollars. These events demonstrate the need for constant security monitoring and rapid software updates in the cryptocurrency ecosystem.
***
The material has been prepared solely for informational purposes and does not constitute financial advice or recommendation.
