BTCPay Server Blocks Remote Lightning Node Access After LND Vulnerability Exploited by Hackers

LND users are urged to check nodes for unauthorised payments and suspicious channel activity.

Advertisement
Written by Rahul Dhingra, Edited by Rohan Pal | Updated: 10 August 2026 15:42 IST
Highlights
  • Attackers exploited leaked LND credentials to access node funds
  • BTCPay says Lightning payments can continue during the restriction
  • Operators using external access must change credentials separately

BTCPay’s latest patch automatically generates fresh LND credentials for affected installations

Photo Credit: Unsplash/Mariia Shalabaieva

The BTCPay Server has currently blocked remote access to nodes on the Lightning Network that use Lightning Network Daemon (LND) software due to a vulnerability being exploited by hackers to steal credentials and transfer funds. BTCPay says that this ban will prevent external wallets like Zeus from accessing the node via the BTCPay Server domain Tor onion URL on Docker deployments. According to BTCPay, Lightning payments could continue while the company planned to roll out remote access once it deemed it safe to do so. Project developers recommended that node operators conduct audits for unauthorised payments, unusual channel closures, unknown peers, and any other imbalances in their balances.

Developers Urge Node Operators to Rotate Credentials and Audit Funds

According to BTCPay, the vulnerability allowed an attacker from afar to obtain “macaroon” credential files used to access LND, a software implementation of the Lightning Network. BTCPay noted that the leaked credentials would enable attackers to control an LND node and steal its funds. As mentioned in the project's security advisory, the 2.4.2 version includes LND version 0.21.1, which automatically generates new macaroon credentials for all standard BTCPay installations. 

Advertisement

The security alerts suggested that operators should look for any unauthorised transactions, unexpected channel closures, suspicious peers, and differences in the on-chain or Lightning balance records.

BTCPay further noted that operators who expose LND using their own reverse proxy, Tor service, forwarded port, or some other method apart from BTCPay need to change their credentials independently. The development team pointed out that the installation of the patch doesn't mean closing independent access paths for the operators. 

The CEO of the Foundation, Zach Herbert, confirmed with a post on X that the hardware wallet startup's Lightning node had been emptied overnight. Later on, he clarified that only its Lightning channels had been drained and not its hot wallet.

Another publication on Bitcoin, Citadel21, reported that the Lightning node from their platform had been swept. The operators did not disclose the amount stolen and further stated, “This is an ongoing attack on BTCPayserver users. Citadel21's lightning node was just swept. Fortunately, there were not many funds there, due to cautionary steps before BIP-110 activation. Praying for all other affected users.”

Advertisement

The BTCPay breach is the latest security incident involving widely used Bitcoin products, following a Coldcard hardware-wallet flaw reported last week. According to Galaxy Digital's chief researcher, Alex Thorn, at least 15 different hackers have used this Coldcard vulnerability, as per the reports received after the incident. It is estimated that the damage caused by this Coldcard exploit amounts to $100 million (roughly Rs. 952 crore). 

Cryptocurrency is an unregulated digital currency, not a legal tender and subject to market risks. The information provided in the article is not intended to be and does not constitute financial advice, trading advice or any other advice or recommendation of any sort offered or endorsed by NDTV. NDTV shall not be responsible for any loss arising from any investment based on any perceived recommendation, forecast or any other information contained in the article.

 

Also seeCryptocurrency Prices across Indian exchanges

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement

Related Stories

Popular Mobile Brands
  1. Moto Pad 70 Goes Official in India: See Price, Specifications
  2. iQOO 16T Early Leak Reveals Details of Rear Camera Unit
  3. Samsung Galaxy Tab S12 Series Renders Leak With New Wallpaper
  4. Amazon Freedom Sale 2026: Best Deals on Mechanical Keyboards
  5. Boat CineHead F1 Pro With Google TV 5.0 Arrives in India: See Price
  6. Here's When the iQOO Z11S Will Launch: See Expected Specs, Design
  7. Lenovo Lecoo P900A Listed Online; Price, Specifications Revealed
  8. Apple Pay Could Launch in India by October Without UPI Support
  9. OnePlus 16 Launch Could Be Imminent as Oppo-Linked Model Gets 5G Approval
  10. GTA 6 Pre-Orders Had an 'Exceptional' Start, Says Take-Two
  1. Take-Two CEO Strauss Zelnick Explains Why GTA 6 Is Not Getting a Disc Version
  2. Redmi 17 5G Launched Globally With 7,500mAh Battery, Snapdragon 4 Gen 5 Chipset, Redmi 17 4G Tags Along: Price, Features
  3. Amazon Freedom Sale 2026: Best Deals on Mechanical Keyboards From RedGear, EvoFox, and More
  4. Brazil's Central Bank Proposes 24-Hour Holds on High-Value Crypto Transfers
  5. Amazon Great Freedom Sale 2026: Best Deals on Gaming Monitors From Lenovo, BenQ, LG, and More
  6. Boltt Ace 5G and Evo Camera Details Revealed Ahead of August 25 India Launch
  7. Amazon Great Freedom Sale 2026: Best Deals on Tablets Under Rs. 30,000 From Samsung, Lenovo, and More
  8. Amazon Great Freedom Sale 2026: Best Deals on Fire TVs
  9. Redmi Note 17 4G Price Revealed via Retail Listing; Could Feature 6.83-Inch Display, 7,700mAh Battery
  10. Apple Pay Could Launch in India by October Without UPI Support: Report
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.