← Radar

Incident case file

Sign in to watch

BTCPay Server LND Macaroon Credential Exposure — Active Exploitation

Incident date 2026-08-06Last updated Aug 14, 2026

5 views

ActiveBitcoinLightning NetworkCritical vulnerability — active exploitationCluster: BTCPAY-VULN-2026-08

Estimated loss

$0

Victims identified

2
Victim group joining is coming soon.

Investigation

40%

Facts and investigation

Ledger

Attacker

MISSING — no attacker address or identity has been publicly disclosed by BTCPay Server or the Bitcoin Red Team.

Funds moved to

MISSING — BTCPay Server has explicitly and repeatedly declined to disclose the total amount stolen, the number of affected installations, or any attacker-controlled addresses. IMPORTANT NOTE: the $0 amount_lost_usd field above reflects data unavailability, NOT a confirmed zero-loss outcome — funds ARE confirmed to have been stolen from at least 2 named victims, but no dollar figure has been released. At least 2 confirmed victims: Foundation (Passport Prime hardware wallet maker; CEO Zack Her

Linked

The vulnerability allowed unauthenticated access to LND '.macaroon' credential files on affected BTCPay Server deployments, giving attackers full control over the associated Lightning nodes and the ability to drain their payment channels. The risk was specific to deployments using LND (Lightning Network Daemon) as their Lightning backend; BTCPay's standard on-chain Bitcoin wallet functionality was not impacted. The bug was discovered not through a formal security audit or AI-assisted code review

Chronology

1 beat
  1. Prior to August 7, 2026: Attackers begin exploiting a previously unknown, critical vulnerability in BTCPay Server, the widely used open-source, self-hosted Bitcoin and Lightning payment processor. The flaw permits unauthenticated access to LND '.macaroon' credential files on vulnerable deployments, granting attackers full remote control over affected Lightning nodes and the ability to drain their payment channels; the standard BTCPay on-chain Bitcoin wallet functionality remains unaffected by this specific flaw. The vulnerability is discovered not through a scheduled security audit but by accident: developer Craig Raw, creator of the Sparrow Wallet software, personally experiences a fund loss and, upon investigating his own server logs, traces the root cause back to this credential-exposure flaw. Foundation, maker of the Passport Prime hardware wallet, reports via CEO Zack Herbert that its own Lightning node was drained overnight — discovered by the company before the public vulnerability alert was issued. Citadel21, a Bitcoin-focused publication run by the pseudonymous Hodlonaut, separately reports that its Lightning node was also swept, though comparatively limited funds were exposed owing to precautionary balance-management practices related to a possible future activation of the proposed BIP-110 soft fork. August 7, 2026: BTCPay Server issues an emergency public security advisory via its official X account, stating plainly: 'There is a critical vulnerability being actively exploited on BTCPay Server, which can result in the loss of funds. Please update your BTCPayServer to 2.4.2 by going to Admin Dashboard -> Server -> Maintenance -> Update & verify the 2.4.2 version string in the footer. If you are unable to update right away, turn off your BTCPay Server to prevent unauthorized access until you can update.' The project simultaneously releases version 2.4.2, containing the security fix, along with detailed remediation guidance: update the companion wallet-indexing service NBXplorer to version 2.6.10, refresh and rotate all LND macaroon credentials and Lightning authentication strings, and migrate any funds held in BTCPay-generated hot wallets to newly created wallets as a precaution against any credentials that may have already been compromised by attackers prior to patching. The disclosure arrives closely on the heels of the ongoing, separate Coldcard hardware-wallet firmware exploit dominating Bitcoin-security news that same week, prompting public commentary — including from Hodlonaut himself — speculating about whether Bitcoin self-custody and infrastructure tooling is being systematically targeted: 'Coldcard and BTCPayserver. These are enthusiast/hardcore tools, used by the people who live and bleed Bitcoin. This does not feel like chance.' As of the close of the reporting window, BTCPay Server has explicitly and repeatedly declined to disclose the total amount of funds stolen, the total number of affected server installations, or any attacker-controlled wallet addresses — a position independently confirmed by multiple tier-1 outlets, including The Block and Bitcoin.com, both stating plainly that 'figures for this exploit have not been released.' A comprehensive post-mortem report from the Bitcoin Red Team investigative group is understood to be forthcoming but had not yet been published at the time of this report's compilation.

Sources and coverage

Victim testimonies

No testimonies yet.

+ Add my testimony → (coming soon)