Skip to content

Bitcoin payment processor BTCPay Server has confirmed a critical vulnerability that resulted in funds being stolen, urging LND users to upgrade immediately.

Aug 9, 14:58

August 9, BTCPay Server released an emergency security advisory stating that all versions prior to 2.4.2 (including the 2.4.2 release candidate) have a critical vulnerability. It has been confirmed that this vulnerability has been actively exploited by attackers, resulting in the theft of user funds. This vulnerability could allow an unauthenticated remote attacker to obtain the LND (Lightning Network Daemon) .macaroon credential file, thereby taking control of the LND node and transferring funds.

The official announcement confirmed that the vulnerability has been actively exploited, leading to the theft of user funds. Users of LND are urged to immediately upgrade to BTCPay Server 2.4.2 and LND 0.21.1. The BTCPay Server on-chain wallet itself is not affected, and the exact amount stolen has not been disclosed by the officials.

Public information indicates that BTCPay Server is a free, open-source, self-hosted Bitcoin payment processor that focuses on providing feeless, intermediary-free Bitcoin payment solutions for sovereign individuals and businesses. A core contributor to the protocol once estimated that there may be tens of thousands of operational BTCPay Server instances worldwide. Its GitHub repository has been downloaded over 1 million times.

Source