BTCPay Server has released an urgent security update to version 2.4.2, addressing what it calls a critical vulnerability that gave attackers the ability to access LND credential files without any authentication. The exploit has already been used in the wild to drain Lightning wallets belonging to Bitcoin merchants, making this more than just a theoretical risk. The open-source payment platform is now urging every user who runs a Lightning-integrated BTCPay instance to upgrade their server without delay.
The LND Credential Bug in Focus
BTCPay Server is one of the most widely used self-custodial payment processors in the Bitcoin ecosystem, allowing businesses to accept cryptocurrency directly without relying on third-party custodians. For merchants using the Lightning Network, the server relies on LND — the Lightning Network Daemon — to manage payment channels, invoices, and wallet keys. Those keys and credentials are stored in configuration files on the server, and under normal circumstances they are protected by strict access controls.
The bug patched in version 2.4.2, however, broke that protection in a severe way. The vulnerability reportedly allowed an unauthenticated remote attacker to read the LND credential files simply by sending crafted requests to a vulnerable BTCPay instance. With those credentials in hand, an attacker could, in effect, impersonate the node operator and take full control of the Lightning node, including moving funds.
Because the issue required no login or special privileges, it completely bypassed the security barriers that BTCPay users rely on. While the exact technical details are still being disclosed in patches and advisories, the potential impact was immediate: any merchant with a vulnerable version and an active Lightning wallet could have their funds swept out from under them.
How Lightning Wallets Got Drained
According to reports, attackers were quick to exploit the credential exposure before the patch was widely distributed. In at least some cases, merchants discovered that their Lightning wallets had been emptied, with funds leaving through unapproved channel operations and payment routes. For businesses that depend on lightning-fast transactions and bitcoin settlement, the losses were not just technical — they hit cash flow directly.
The attack chain appears deceptively simple: identify a BTCPay server running a vulnerable version, retrieve the LND credentials remotely, then use those credentials to issue commands that transfer or close out channel balances. Since Lightning Network funds are held in multisignature channels, full control over the node usually gives an attacker the ability to unilaterally close channels and sweep the bitcoin to an address they control.
This is not the first time Lightning software has faced security challenges, but it is a stark reminder that self-custody comes with serious responsibilities. BTCPay users are their own banks, and when critical files are exposed, there is no central support team to reverse transactions or refund stolen funds.
What BTCPay Server Users Must Do Now
The first and most important step is to update to BTCPay Server version 2.4.2 immediately. The patch is designed to close the authentication gap and prevent unauthorized access to LND credential files. Because the vulnerability may already be actively exploited, waiting or postponing the upgrade could expose your node to the same fate that claimed other merchants' wallets.
After updating, users should take a careful look at their Lightning balance and channel state. Look for any transactions, channel closures, or payment routes that you did not initiate. If anything looks suspicious, the safest course is to force-close your channels and move the remaining funds to a secure wallet.
In addition to upgrading, consider the following security measures:
- Rotate all LND credentials and reissue the macaroon files used for authentication.
- Enable two-factor authentication for any server admin panels or SSH access.
- Keep your BTCPay Server software updated on a regular cadence, not just when critical patches are announced.
- Monitor your Lightning node activity with alerts for unusual channel closures or large outbound payments.
- Use a dedicated user account with minimal privileges to run the BTCPay and LND processes.
The threat is real and the window for protecting your funds is narrow. If you run a Lightning-enabled BTCPay Server, update now, verify your balances, and assume that your credentials may have been exposed until proven otherwise.
Key Takeaways
This incident delivers a clear message to the Bitcoin community: even the most trusted open-source infrastructure can carry hidden flaws, and timely updates are non-negotiable. BTCPay Server acted quickly to patch the critical LND credential bug, but the fact that attackers were already draining Lightning wallets demonstrates how dangerous delayed upgrades can be.
For merchants, the lesson goes beyond this single vulnerability. Running a self-custodial node means taking ownership of security practices, from prompt patching to ongoing monitoring. The Lightning Network remains an exciting and efficient payment layer, but incidents like this are a reminder that it is still evolving rapidly.
Stay safe out there: update to version 2.4.2, audit your Lightning channels, and keep an eye on the BTCPay Server announcement channels for any further guidance.
Zyra