A critical vulnerability in BTCPay Server allowed attackers to drain Lightning Network nodes belonging to merchants and publishers late Friday, capping one of the most turbulent weeks for Bitcoin infrastructure security.

The exploit targeted deployments running LND, the most widely used Lightning node software, by exposing credential files known as ".macaroon" files. With access to those files, an unauthenticated remote attacker could seize control of a Lightning node, close its channels, and sweep the funds.

BTCPay Server confirmed that funds were stolen and urged all operators running LND to update immediately to version 2.4.2 or take their servers offline.

Known Victims

Hardware-wallet manufacturer Foundation was among the first to report losses. CEO Zach Herbert said attackers drained the company's BTCPay Lightning node overnight, closing channels and sweeping balances. The company's on-chain hot wallet was untouched.

Citadel21, a Bitcoin publication run by pseudonymous commentator hodlonaut, also reported its Lightning node had been emptied, though it noted the holdings were minimal.

BTCPay has not disclosed the total number of affected users or the aggregate value of stolen funds.

AI Red Team Connection

The vulnerability had already been responsibly disclosed to BTCPay by members of the Bitcoin Red Team, a volunteer security initiative that has spent the week pointing frontier AI models at Bitcoin codebases. The group — which includes developers Craig Raw, Rob Hamilton, Calle, and Evan Kaloudis — reportedly filed thousands of vulnerability findings across hundreds of Bitcoin projects.

BTCPay credited the Red Team with discovering and reporting the issue. However, by the time the public warning went out, attackers were already exploiting the flaw against live servers, suggesting the vulnerability was independently discovered by malicious actors.

Scope Limited to Lightning

BTCPay narrowed the impact after its initial alert. Standard on-chain wallets generated inside BTCPay — including hot wallets — are not affected by the credential flaw. The exposure applies specifically to deployments using LND, though funds held in LND's own on-chain wallet can also be at risk because they sit under the compromised Lightning node's control.

BTCPay said it would publish a full technical postmortem in the coming days, once operators have had time to patch.

Broader Context

The incident follows a series of security scares across the Bitcoin ecosystem this week. The Coldcard hardware wallet exploit, the Boltz Bridge shutdown after AI-discovered vulnerabilities, and now the BTCPay Lightning drain have collectively raised questions about whether AI-assisted vulnerability discovery is outpacing the ecosystem's ability to patch.

For merchants relying on BTCPay Server to accept Bitcoin payments, the message is immediate: update to 2.4.2 or disconnect.