GetChain News
中简 中繁 EN
GetChain News
Toggle sidebar

Security/Hacker

News linked to both this project and an event.

BTCPay Server Hit by Critical Vulnerability Exploit, Supporters Launch Up to 3 BTC Bounty to Recover Stolen Funds

According to The Block, open-source Bitcoin payment processor BTCPay Server disclosed a critical security vulnerability being actively exploited last Friday and urgently requested users to upgrade to version 2.4.2. The vulnerability affects all versions prior to 2.4.2; attackers can use it to steal administrator macaroon authentication credentials of LND nodes, thereby fully controlling the connected Lightning Network wallets. Users such as Foundation and Citadel21 have confirmed that their Lightning node funds were drained, but BTCPay has not publicly disclosed the total amount stolen or the number of affected nodes. Currently, the official release version 2.4.2 has fixed this vulnerability, and on-chain hot wallets are not affected. The BTCPay Server Foundation has donated 0.21 BTC each to security researcher Craig Raw and Bitcoin Red Team to commend their responsible private disclosure of the vulnerability. Meanwhile, BTCPay supporters have promised to provide a bounty incentive of "10% of recovered funds," capped at 3 BTC.

BTCPay Temporarily Restricts Lightning Network Remote Access Due to LND Vulnerability

According to Cointelegraph, BTCPay Server has temporarily restricted public remote connections to Lightning Network nodes due to attackers exploiting a critical vulnerability in LND (Lightning Network Daemon) to steal node credentials and transfer funds. Version 2.4.2 has upgraded to LND 0.21.1 and automatically rotates macaroon credentials in standard installations. The project team reminds operators to check for abnormal payments, channel closures, and balance changes as soon as possible; if nodes are exposed via self-built reverse proxies, Tor services, or port forwarding, relevant credentials must also be manually replaced. Currently, Foundation and Citadel21 have reported node fund losses, but the specific scale of losses has not yet been disclosed.

BTCPay Server Temporarily Restricts Public Remote Connections to LND Nodes, Vulnerability Causes Credential Leakage and Fund Theft

Bitcoin payment processing service BTCPay Server has temporarily restricted public remote connections to Lightning Network nodes running Lightning Network Daemon (LND) software. Attackers exploited a severe vulnerability to obtain credentials and transfer funds. The number of affected operators and the total amount stolen have not yet been disclosed. This restriction affects external wallets such as Zeus that connect via BTCPay Server domains or Tor onion addresses in Docker deployments, but Lightning Network payments can still continue. BTCPay Server stated that remote access functionality will be restored once security is confirmed. BTCPay Server 2.4.2 will install LND 0.21.1 and automatically regenerate macaroon credentials during standard installation. Foundation and Citadel21 have respectively disclosed that funds from their Lightning Network nodes were swept. Foundation stated that hot wallets were not affected, and the specific amounts of losses have not been disclosed.