BTCPay Server Fixes critical LND credential vulnerabilities to prevent lightning wallets from being stolen
2026-08-12 00:45:29
According to CoinMeta, BTCPay Server has released version 2.4.2, which fixes a critical vulnerability that allowed unauthorized remote access to LND credential files. Attackers exploited this vulnerability to steal merchants' Lightning wallets. The project's release note describes a serious vulnerability involving macaroon files, which are used to manage access permissions for LND. BTCPay supporters also offer a recovery bonus equal to 10% of the returned funds, with a cap of 3 BTC. At current prices, the maximum reward is approximately $190,000. This incident is not a Bitcoin protocol vulnerability but rather a server-side security issue affecting certain servers that use LND and BTCPay Server settings. Affected merchants should update their systems as soon as possible to ensure security.
Source:Internet
This content is for market information only and does not constitute investment advice.
Follow HQYC official accounts to stay updated

Hot Articles
Refresh

'No longer a distant place': F2Pool Co-founder Chun Wang joins SpaceX's 2-year mission to Mars
05-22 18:25

Polymarket Targets Japan Approval Despite Gambling Laws
05-22 18:00

ZachXBT flags suspected exploit involving Polymarket's UMA adapter contract on Polygon
05-22 17:57

ZachXBT flags $520K Polymarket exploit on Polygon, team says funds are safe
05-22 17:24

Verus bridge exploiter returns 4,052 ETH, retains $2.8 million bounty: onchain analyst
05-22 17:24



