{"id":18389,"date":"2026-08-08T08:11:00","date_gmt":"2026-08-08T15:11:00","guid":{"rendered":"https:\/\/jasonsblog.ddns.net\/?p=18389"},"modified":"2026-08-08T08:17:12","modified_gmt":"2026-08-08T15:17:12","slug":"another-bitcoin-infrastructure-exploit-hits-this-time-draining-lightning-payment-servers","status":"publish","type":"post","link":"https:\/\/jasonsblog.ddns.net\/index.php\/2026\/08\/08\/another-bitcoin-infrastructure-exploit-hits-this-time-draining-lightning-payment-servers\/","title":{"rendered":"Another Bitcoin Infrastructure Exploit Hits, This Time Draining Lightning Payment Servers"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">The timing of this LND hack and funding of the Red Team are incredibly suspect going into the BIP-110 soft fork. And interestingly, NVK, Coinkite CEO Rodolfo Novak, was on the board but stepped down five days ago after the Coldcard debacle over the seed randomness flaw and losing people&#8217;s life savings, over $100 million. This creates fear of self-custody, driving people to put coins on exchanges, and is the goal to steal from them if there is a fork which leads to another version of <a href=\"https:\/\/jasonsblog.ddns.net\/index.php\/2025\/09\/12\/the-case-for-the-only-cryptocurrency-of-value-bitcoin\/\" target=\"_blank\" rel=\"noreferrer noopener\">Bitcoin<\/a>? If the soft fork leads to a lasting chain split, and then a hard fork version on the BIP-110 side, there would be a mechanism to split the tokens for both networks to protect from a replay attack on the opposite chain. But will the exchanges take one chain for themselves? If they claimed the BIP-110 side they could then liquidate all of them to manipulate the price. It is a fact that this is going to scare away a lot of normal people from wanting to touch the fiat exit that is Bitcoin, and be very afraid of self-custody, which governments are keen to mandate.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/www.coindesk.com\/tech\/2026\/08\/08\/another-bitcoin-infrastructure-exploit-hits-this-time-draining-merchant-lightning-nodes\" target=\"_blank\" rel=\"noreferrer noopener\">https:\/\/www.coindesk.com\/tech\/2026\/08\/08\/another-bitcoin-infrastructure-exploit-hits-this-time-draining-merchant-lightning-nodes<\/a><\/p>\n\n\n<div class=\"wp-block-ub-divider ub_divider ub-divider-orientation-horizontal\" id=\"ub_divider_ad5d053f-77d5-43ba-82dc-8912a691b1d8\"><div class=\"ub_divider_wrapper\" style=\"position: relative; margin-bottom: 2px; width: 100%; height: 2px; \" data-divider-alignment=\"center\"><div class=\"ub_divider_line\" style=\"border-top: 2px solid #ccc; margin-top: 2px; \"><\/div><\/div><\/div>\n\n\n<h5 class=\"wp-block-heading\">BTCPay told users running LND to update immediately or take servers offline after attackers stole credentials that can control Lightning wallets and move funds.<\/h5>\n\n\n\n<p class=\"wp-block-paragraph\">By Shaurya Malwa<\/p>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/www.coindesk.com\/_next\/image?url=https%3A%2F%2Fcdn.sanity.io%2Fimages%2Fs3y3vcno%2Fproduction%2Ff2f6731511c468648ae94fe05f6331efb1318c2f-1500x1071.jpg%3Frect%3D0%2C114%2C1500%2C844%26w%3D1920%26h%3D1080%26auto%3Dformat&amp;w=3840&amp;q=75\" alt=\"Lightning, represented by a bolt, is a network that runs atop Bitcoin. (Max Bender\/Unsplash)\"\/><figcaption class=\"wp-element-caption\">Another bitcoin infrastructure exploit hits, this time draining merchant Lightning nodes. (Max Bender\/Unsplash)<\/figcaption><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">Summary<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Attackers exploited a critical vulnerability in BTCPay Server to steal funds from Lightning nodes running LND, prompting urgent calls to update to version 2.4.2 or take servers offline.<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">A rough week for bitcoin&#8217;s software is getting worse, this time hitting merchants who accept bitcoin <a href=\"https:\/\/www.coindesk.com\/price\/bitcoin\">BTC$65,106.17<\/a> payments through Lightning, a separate network built on top of bitcoin for instant, low-cost transfers.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Attackers drained Lightning nodes running behind BTCPay Server late on Friday after exploiting a critical vulnerability that exposed the credentials protecting them, the team <a href=\"https:\/\/x.com\/i\/status\/2085755643659522240\" target=\"_blank\" rel=\"noreferrer noopener\">said in an X post<\/a>.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">BTCPay confirmed funds were stolen and told anyone running LND, the most widely used software for operating a Lightning node, to update immediately to version 2.4.2 or take the server offline.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The project has not disclosed how many users were hit or how much bitcoin was taken.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The flaw allowed an unauthenticated remote attacker to obtain \u201c.macaroon\u201d files, or credentials that give software permission to interact with an LND Lightning node. BTCPay said the attacks it reviewed targeted those files, which could then be used to take control of the node and move funds.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Hardware-wallet maker Foundation was among the victims. Chief Executive Zach Herbert <a href=\"https:\/\/x.com\/zherbert\/status\/2085788368365875378\" target=\"_blank\" rel=\"noreferrer noopener\">said attackers<\/a> drained the company&#8217;s BTCPay Lightning node overnight, closing its channels and sweeping the funds. Its BTCPay on-chain hot wallet was untouched.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Citadel21, the bitcoin publication run by pseudonymous commentator hodlonaut, <a href=\"https:\/\/x.com\/hodlonaut\/status\/2085784250293317636\" target=\"_blank\" rel=\"noreferrer noopener\">also reported<\/a> that its Lightning node had been swept, though it said little money was held there.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The vulnerability had already been reported to BTCPay by members of the Bitcoin Red Team \u2014 a group of developers that <a href=\"https:\/\/www.coindesk.com\/tech\/2026\/08\/06\/bitcoin-developers-flag-85-critical-bugs-in-an-extremely-bad-situation\">began pointing AI models<\/a> at bitcoin codebases this week and has filed thousands of findings across hundreds of projects since.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">BTCPay credited Red Team members Craig Raw, Rob Hamilton, Calle and Evan Kaloudis with responsibly disclosing the issue and helping analyze it.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The group&#8217;s stated reason for publishing findings quickly was that people outside it would arrive at the same bugs, and by the time BTCPay&#8217;s public warning went out, attackers were already exploiting this one against live servers.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Meanwhile, BTCPay narrowed the scope after its initial alert, saying its standard on-chain wallets, including hot wallets generated inside BTCPay, are not affected by the credential flaw.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The exposure applies specifically to deployments using LND, and funds held inside LND&#8217;s own on-chain wallet can still be at risk because they sit under the compromised Lightning node.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">BTCPay has not yet published technical details of the vulnerability, saying operators need time to patch. A full postmortem is due in the coming days.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>The timing of this LND hack and funding of the Red Team are incredibly suspect going into the BIP-110 soft fork. And interestingly, NVK, Coinkite CEO Rodolfo Novak, was on the board but stepped down five days ago after the Coldcard debacle over the seed randomness flaw and losing people&#8217;s life savings, over $100 million. [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[6],"tags":[],"class_list":["post-18389","post","type-post","status-publish","format-standard","hentry","category-tech"],"blocksy_meta":{"styles_descriptor":{"styles":{"desktop":"","tablet":"","mobile":""},"google_fonts":[],"version":7}},"featured_image_src":null,"author_info":{"display_name":"Jason","author_link":"https:\/\/jasonsblog.ddns.net\/index.php\/author\/jturning\/"},"_links":{"self":[{"href":"https:\/\/jasonsblog.ddns.net\/index.php\/wp-json\/wp\/v2\/posts\/18389","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/jasonsblog.ddns.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/jasonsblog.ddns.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/jasonsblog.ddns.net\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/jasonsblog.ddns.net\/index.php\/wp-json\/wp\/v2\/comments?post=18389"}],"version-history":[{"count":3,"href":"https:\/\/jasonsblog.ddns.net\/index.php\/wp-json\/wp\/v2\/posts\/18389\/revisions"}],"predecessor-version":[{"id":18392,"href":"https:\/\/jasonsblog.ddns.net\/index.php\/wp-json\/wp\/v2\/posts\/18389\/revisions\/18392"}],"wp:attachment":[{"href":"https:\/\/jasonsblog.ddns.net\/index.php\/wp-json\/wp\/v2\/media?parent=18389"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/jasonsblog.ddns.net\/index.php\/wp-json\/wp\/v2\/categories?post=18389"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/jasonsblog.ddns.net\/index.php\/wp-json\/wp\/v2\/tags?post=18389"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}