Understand custody · A documented incident
The File That Became a Key: Theft Through BTCPay Server
On August 7, 2026, the BTCPay Server team released the urgent 2.4.2 update. It fixed a critical vulnerability that attackers had already exploited. Funds were stolen from some Lightning-node operators.
EDITORIAL OVERVIEW · Prepared by the project editors from the sources listed below.
What happened
The issue affected every earlier BTCPay Server version when used with LND, one implementation of the Lightning Network.
An unauthenticated remote attacker could obtain files with the .macaroon extension. These files are not bitcoin, a seed phrase, or an ordinary password. A macaroon is an authorization credential that defines which commands may be performed on a Lightning node.
When such a file carries administrative permissions, its exposure can provide control over LND. The obtained authority could be used to operate the node and move funds under its control.
BTCPay Server confirmed that the vulnerability was exploited, users were affected, and funds were stolen. Its advisory did not state the total loss. Technical details were initially withheld to give operators time to install the fix.
Who was affected
The immediate risk applied to operators running a BTCPay Server version earlier than 2.4.2 together with an LND Lightning node.
BTCPay Server's regular on-chain wallets were not affected by this specific vulnerability, nor were other Lightning implementations. Funds in LND's own on-chain wallet could still be at risk because they belonged to the compromised node.
What the update changed
Version 2.4.2 fixed the vulnerability, upgraded LND to version 0.21.1, and automatically regenerated its administrative macaroons.
The project advised affected operators to update BTCPay Server immediately, inspect balances and transaction history, rotate LND credentials, and take the server offline if an immediate update was impossible.
If an operator had separately exposed LND through a reverse proxy, Tor service, forwarded port, or another route, updating BTCPay Server alone might not close that independently managed access path; those credentials and routes also required review.
A macaroon is neither bitcoin nor a seed phrase, but its permissions could be sufficient to control an LND node.
Sources and verification
Documented fact. The project confirmed exploitation and stolen funds, but its official advisory did not state a total amount lost.
Unless stated otherwise, the text, conclusions, structure and editorial arrangement were created by the project editors. Facts, quotations and source materials remain attributable to their authors and rights holders.
← Back to the rubric