Understand custody · A documented incident

The File That Became a Key: Theft Through BTCPay Server

On August 7, 2026, the BTCPay Server team released the urgent 2.4.2 update. It fixed a critical vulnerability that attackers had already exploited. Funds were stolen from some Lightning-node operators.

EDITORIAL OVERVIEW · Prepared by the project editors from the sources listed below.

What happened

The issue affected every earlier BTCPay Server version when used with LND, one implementation of the Lightning Network.

An unauthenticated remote attacker could obtain files with the .macaroon extension. These files are not bitcoin, a seed phrase, or an ordinary password. A macaroon is an authorization credential that defines which commands may be performed on a Lightning node.

When such a file carries administrative permissions, its exposure can provide control over LND. The obtained authority could be used to operate the node and move funds under its control.

BTCPay Server confirmed that the vulnerability was exploited, users were affected, and funds were stolen. Its advisory did not state the total loss. Technical details were initially withheld to give operators time to install the fix.

Who was affected

The immediate risk applied to operators running a BTCPay Server version earlier than 2.4.2 together with an LND Lightning node.

BTCPay Server's regular on-chain wallets were not affected by this specific vulnerability, nor were other Lightning implementations. Funds in LND's own on-chain wallet could still be at risk because they belonged to the compromised node.

What the update changed

Version 2.4.2 fixed the vulnerability, upgraded LND to version 0.21.1, and automatically regenerated its administrative macaroons.

The project advised affected operators to update BTCPay Server immediately, inspect balances and transaction history, rotate LND credentials, and take the server offline if an immediate update was impossible.

If an operator had separately exposed LND through a reverse proxy, Tor service, forwarded port, or another route, updating BTCPay Server alone might not close that independently managed access path; those credentials and routes also required review.

A macaroon is neither bitcoin nor a seed phrase, but its permissions could be sufficient to control an LND node.

Sources and verification

  1. BTCPay Server: official advisory to update to version 2.4.2
  2. BTCPay Server: incident response and next steps
  3. GitHub: official BTCPay Server 2.4.2 release

Documented fact. The project confirmed exploitation and stolen funds, but its official advisory did not state a total amount lost.

Unless stated otherwise, the text, conclusions, structure and editorial arrangement were created by the project editors. Facts, quotations and source materials remain attributable to their authors and rights holders.

Back to the rubric