
On the night of August 8, hackers drained funds from Lightning Network nodes operating through the BTCPay payment server. Developers confirmed the theft and urged users of the LND software to immediately update to version 2.4.2 or disable the server.
There is a critical vulnerability being actively exploited on BTCPay Server, which can result in the loss of funds.
Please update your BTCPayServer to 2.4.2 by going to Admin Dashboard -> Server -> Maintenance -> Update & verify the 2.4.2 version string in the footer.
If you…
— BTCPay Server (@BtcpayServer) August 7, 2026
Merchants deploy BTCPay independently to accept Bitcoin without intermediaries and connect to the Lightning Network for small transactions. Access to the network node is managed through .macaroon files, which due to a flaw, could be remotely obtained without authorization, giving attackers full control over the node, allowing them to close channels and withdraw funds.
According to developers, the vulnerability is limited to configurations with LND, the most common software for Lightning nodes. Regular BTCPay Bitcoin wallets (including hot wallets) are unaffected, but coins on an LND address are at risk as it is controlled by the compromised node.
The project did not specify how many merchants were affected or the amount lost. A full incident analysis is promised in the coming days.
The issue was discovered during an AI-assisted audit. Members of the volunteer organization Bitcoin Red Team notified BTCPay about the problem in advance. In early August, the group began a large-scale review of Bitcoin project codebases using neural networks, generating thousands of reports.
Foundation Wallet Manufacturer Among Victims
At least two organizations publicly reported losses. Zach Herbert, CEO of hardware wallet manufacturer Foundation, stated that attackers drained the company’s Lightning node on BTCPay overnight. The on-chain wallet was not affected.
How many BTCPay lightning nodes were swept? Our Foundation node was drained overnight by attackers. https://t.co/nt5OFBXB4j
— Zach Herbert 🇺🇸 (@zherbert) August 7, 2026
A similar node breach was confirmed by Bitcoin publication Citadel21, run by commentator hodlonaut. He noted that the node held insignificant amounts.
This is an ongoing attack on BTCPayserver users.
Citadel21’s lightning node was just swept. Fortunately there were not much funds there, due to cautionary steps before BIP-110 activation.
Praying for all other affected users. https://t.co/YhdHhoPncH pic.twitter.com/4iRj1HJptL
— hodlonaut #BIP-110 (@hodlonaut) August 7, 2026
Earlier, on the night of July 31, approximately 500 Coldcard hardware wallet owners had 594.48 BTC (~$38.2 million) stolen.
