BTCPay Server Rotates Credentials After Lightning Exploit
BTCPay’s emergency update rotates credentials on standard installations, while operators with independently managed access routes must take extra steps.
YayaNews contributes financial news and market context through the YayaNews editorial workflow.

BTCPay’s emergency update rotates credentials on standard installations, while operators with independently managed access routes must take extra steps.
BTCPay Server Rotates Credentials After Lightning Exploit
DOGE
$0.07023
0.19%
TRX
$0.3299
0.78%
LINK
$8.33
1.00%
ZEC
$510.37
0.98%
ADA
$0.1985
0.65%
XRP
$1.04
0.60%
ETH
$1,918.64
0.14%
BTC
$64,838.57
0.23%
XMR
$379.89
0.20%
BNB
$603.60
1.51%
XLM
$0.1635
0.37%
SOL
$76.46
2.35%
HYPE
$54.77
0.74%
Written by
Ezra Reguerra
staff writer
Reviewed by
Robert Lakin
staff editor
Written by
Ezra Reguerra
staff writer
Reviewed by
Robert Lakin
staff editor
BTCPay restricts remote Lightning access after attackers steal funds
Latest News
Published
Aug 9, 2026
Foundation and Citadel21 reported drained Lightning nodes, but the total amount stolen and number of affected operators remain unknown.
BTCPay Server has temporarily restricted public remote connections to Lightning Network nodes running Lightning Network Daemon (LND) software after attackers exploited a critical vulnerability to obtain credentials and move funds.
BTCPay
said
the restriction prevents external wallets such as Zeus from connecting through a BTCPay Server domain or Tor onion address on Docker deployments. BTCPay said Lightning payments can continue and that it plans to restore the remote-access option when it considers it safe.
Version 2.4.2 installs LND version 0.21.1 and automatically regenerates the macaroon credentials on standard BTCPay installations. The project advised operators to check for unauthorized payments, unexpected channel closures, unfamiliar peers and discrepancies in their onchain or Lightning balances.
The BTCPay breach is the latest security incident involving widely used Bitcoin products, following a Coldcard hardware-wallet flaw linked to
more than $100 million in confirmed losses
. The separate incidents affected software surrounding Bitcoin rather than the network’s underlying protocol.
Update automatically rotates Lightning credentials
BTCPay said the vulnerability allowed an unauthenticated remote attacker to obtain “macaroon” credential files used to control LND, an implementation of the Lightning Network. The project said the exposed credentials could allow attackers to take control of an LND node and move its funds.
According to the project’s security advisory, version 2.4.2 installs LND version 0.21.1 and automatically regenerates macaroon credentials on standard BTCPay installations. It advised operators to check for unauthorized payments, unexpected channel closures, unfamiliar peers and discrepancies between their records and onchain or Lightning balances.
Related:
Coldcard exploit pushes July losses to $247M as second-worst month of 2026
BTCPay also said operators exposing LND through their own reverse proxy, Tor service, forwarded port, or another route outside BTCPay must rotate their credentials separately. The project said installing the update does not close access routes managed independently by the operator.
At least two operators publicly reported losses. Foundation CEO Zach Herbert
said
the hardware-wallet company’s Lightning node was drained overnight. He
later
clarified
that its hot wallet was unaffected, while its Lightning channels were closed and the funds swept.
Bitcoin publication Citadel21 also
reported
that its Lightning node had been swept. Neither operator disclosed the amount lost.
Magazine:
10 weirdest things ever tokenized... including farts
Subscribe to daily byte-sized crypto news from Cointelegraph
Subscribe
Cointelegraph is committed to independent, transparent journalism. This news article is produced in accordance with Cointelegraph’s
Editorial Policy
and aims to provide accurate and timely information. Readers are encouraged to verify information independently.
Hackers
Hacks
Security
Cybersecurity
Bitcoin
More on the subject
Bitcoin will never fall below $60K again: Nansen founder
17 hours ago
Ciaran Lyons
Bitcoiners turn to dice throws as self-custody setups are re-evaluated
Aug 7, 2026
Charles Bennett
Binance Bitcoin volume ratio hits record as futures outweigh spot eight times over
Aug 7, 2026
William Suberg
Bitcoin will never fall below $60K again: Nansen founder
17 hours ago
Ciaran Lyons
Bitcoiners turn to dice throws as self-custody setups are re-evaluated
Aug 7, 2026
Charles Bennett
Binance Bitcoin volume ratio hits record as futures outweigh spot eight times over
Aug 7, 2026
William Suberg
Original YayaNews editorial coverage, published for informational purposes.
This article is sourced from CoinTelegraph. It is for informational purposes only and does not constitute investment advice.
Topics & Symbols
Continue Reading
Related Reading
Upbit Lists PROM with KRW and USDT Trading Pairs, Opening New Opportunities for Mid-Cap Tokens
Upbit announced the addition of PROM KRW and USDT trading pairs, with a market cap of approximately $43.5 million. This article analyzes the significance, project background, and market impact for investors.

SEC Prepares Major Crypto Plan as Clarity Act Stalls: What It Means for Markets
As the Clarity Act remains gridlocked, the SEC is reportedly preparing a significant crypto regulatory plan. This article analyzes potential new rules covering DeFi, stablecoins, and exchanges, market reactions, and the global competitive pressures shaping U.S. oversight.

Binance Launches DOSUSDT Perpetual Contract: Market Impact and Investment Strategy Analysis
Binance announced the listing of the USDⓈ-M DOSUSDT perpetual contract on August 11, 2026. This article analyzes the announcement background, market reactions, and investment risks to help investors seize opportunities.

Ireland Plans Industry Standards for Illicit Crypto Use
The strategy prepared by the Irish government’s finance department included industry standards on crypto used for gambling and strengthening AML/CFT measures in certain cases.
