

BTCPay Server has temporarily blocked remote access to Lightning Network nodes using Lightning Network Daemon (LND) software after hackers exploited a vulnerability that could expose sensitive authentication credentials and potentially drain funds. The restriction affects external wallets such as Zeus that connect to nodes through BTCPay Server’s Tor onion URL on Docker deployments. BTCPay said Lightning payments could continue while it works on restoring remote access safely. The project has advised node operators to check for unauthorised payments, unexpected channel closures, unknown peers and discrepancies between on-chain and Lightning balances.
The vulnerability reportedly allowed remote attackers to obtain LND “macaroon” credential files, which can provide control over an LND node. BTCPay’s security guidance recommends upgrading to version 2.4.2, which includes LND 0.21.1 and automatically generates new macaroon credentials for standard BTCPay installations. Operators who expose LND through their own reverse proxy, Tor service or forwarded port must rotate those credentials separately. The incident has also reportedly affected individual Lightning nodes, highlighting the need for operators to audit their funds and secure every independent access path.



















Comments (0)
No comments yet
Be the first to comment!