LND users are urged to check nodes for unauthorised payments and suspicious channel activity.
BTCPay’s latest patch automatically generates fresh LND credentials for affected installations
Photo Credit: Unsplash/Mariia Shalabaieva
The BTCPay Server has currently blocked remote access to nodes on the Lightning Network that use Lightning Network Daemon (LND) software due to a vulnerability being exploited by hackers to steal credentials and transfer funds. BTCPay says that this ban will prevent external wallets like Zeus from accessing the node via the BTCPay Server domain Tor onion URL on Docker deployments. According to BTCPay, Lightning payments could continue while the company planned to roll out remote access once it deemed it safe to do so. Project developers recommended that node operators conduct audits for unauthorised payments, unusual channel closures, unknown peers, and any other imbalances in their balances.
According to BTCPay, the vulnerability allowed an attacker from afar to obtain “macaroon” credential files used to access LND, a software implementation of the Lightning Network. BTCPay noted that the leaked credentials would enable attackers to control an LND node and steal its funds. As mentioned in the project's security advisory, the 2.4.2 version includes LND version 0.21.1, which automatically generates new macaroon credentials for all standard BTCPay installations.
The security alerts suggested that operators should look for any unauthorised transactions, unexpected channel closures, suspicious peers, and differences in the on-chain or Lightning balance records.
BTCPay further noted that operators who expose LND using their own reverse proxy, Tor service, forwarded port, or some other method apart from BTCPay need to change their credentials independently. The development team pointed out that the installation of the patch doesn't mean closing independent access paths for the operators.
The CEO of the Foundation, Zach Herbert, confirmed with a post on X that the hardware wallet startup's Lightning node had been emptied overnight. Later on, he clarified that only its Lightning channels had been drained and not its hot wallet.
Another publication on Bitcoin, Citadel21, reported that the Lightning node from their platform had been swept. The operators did not disclose the amount stolen and further stated, “This is an ongoing attack on BTCPayserver users. Citadel21's lightning node was just swept. Fortunately, there were not many funds there, due to cautionary steps before BIP-110 activation. Praying for all other affected users.”
The BTCPay breach is the latest security incident involving widely used Bitcoin products, following a Coldcard hardware-wallet flaw reported last week. According to Galaxy Digital's chief researcher, Alex Thorn, at least 15 different hackers have used this Coldcard vulnerability, as per the reports received after the incident. It is estimated that the damage caused by this Coldcard exploit amounts to $100 million (roughly Rs. 952 crore).
Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.