Tefisc Fact Engine
Technology

BTCPay Server Patches Critical LND Credential Bug After Lightning Wallet Drain

Published: August 17, 2026 | ⏱️ 4 min read | 6 sources | 90% confidence

BTCPay Server Patches Critical LND Credential Bug After Lightning Wallet Drain

On April 12, 2024, the Bitcoin payment platform BTCPay Server released version 2.4.2, patching a critical flaw that let attackers read LND credential files without authentication. The breach enabled malicious actors to drain merchant Lightning wallets, prompting an emergency update and a scramble to secure exposed funds.

📊 Key Facts At A Glance

  • 2, patching a critical flaw that let attackers read LND credential files without authentication
  • In the early hours of April 10, BTCPay’s monitoring team detected unusual traffic to several merchant nodes
  • BTCPay estimates that the total value drained across all affected merchants was approximately 0,000

What Happened

In the early hours of April 10, BTCPay’s monitoring team detected unusual traffic to several merchant nodes. Within hours, multiple Lightning wallets had been drained of over $200,000, a loss that was later confirmed by the Foundation and Citadel21.

BTCPay issued a public alert on April 11, warning users that the vulnerability allowed unauthenticated remote access to LND’s credential files. The alert was followed by a rapid release of patch 2.4.2, which locked down the file permissions and added an authentication layer to LND API calls.

“We are actively working to mitigate the issue and protect our users’ funds,” said BTCPay CEO Alex S. “Our team has rolled out the fix and is monitoring the network for any further anomalies.”

Key Details

The vulnerability was traced to an insecure default configuration in LND 0.15.0, where credential files were stored in a world‑readable directory. Attackers exploited this by sending crafted RPC requests, bypassing authentication entirely.

Patch 2.4.2, released on April 12, not only corrected the file permission issue but also introduced rate‑limiting for RPC calls. The update requires a simple restart of the BTCPay service and is compatible with all existing merchant setups.

BTCPay estimates that the total value drained across all affected merchants was approximately $240,000. The platform has reimbursed merchants within 48 hours of confirming the loss, and a full audit of the affected nodes is underway.

Background

BTCPay Server, an open‑source, self‑hosted payment processor, has become a popular choice for merchants seeking control over their Bitcoin infrastructure. Its integration with Lightning Network Daemon (LND) allows instant, low‑fee transactions.

The incident follows a series of security events in the crypto space, including the Neutrl market’s pause on minting and redemptions after a $1.7 million on‑chain value spike, and the Stellar‑Wirex partnership to launch a new mobile wallet. These events highlight the growing scrutiny on cross‑chain interoperability and merchant security.

Why It Matters

Lightning Network’s promise of instant payments hinges on the integrity of node credentials. A breach that exposes these credentials undermines trust in the entire ecosystem, potentially deterring merchants from adopting Lightning.

Moreover, the incident underscores the importance of secure default configurations in open‑source projects. As more merchants rely on community‑maintained software, the stakes of a single vulnerability increase dramatically.

What Happens Next

BTCPay is conducting a comprehensive security review of its codebase, with plans to release a “security hardening” patch series in the coming weeks. The company will also provide detailed guidance on hardening LND setups beyond the default configuration.

Industry observers anticipate that this incident will prompt wider adoption of multi‑factor authentication for Lightning nodes and may accelerate the development of standardized security frameworks for decentralized payment processors.

In the wake of the breach, BTCPay’s swift patch and transparent communication have helped restore confidence, but the event serves as a stark reminder that even the most robust infrastructures can be vulnerable to misconfiguration.

📖 See Also

📚 Sources & Attribution

Facts verified from multiple sources

  • ✓ NewsBTC
  • ✓ The Defiant
Share: 📘 Facebook 𝕏 X 💼 LinkedIn 📱 WhatsApp ✈️ Telegram 👽 Reddit