Skip to main content
AVOID.NET

BTCPay Server — Lightning LND Macaroon Exploit (August 2026)

avoid.net/btcpay-server-lightning-lnd-macaroon-exploit-august-202647/100·82% conf.
[AI-DRAFTED · AWAITING VERIFICATION]

Auto-generated score, not yet verified against the scoring model. Under review — treat as indicative, not a verdict.

anchored·3a1AWW…FHkm

Summary

In August 2026, a critical, actively exploited vulnerability in BTCPay Server allowed unauthenticated remote attackers to obtain LND macaroon credential files, granting full administrative access to victim Lightning nodes and enabling fund theft. BTCPay Server released emergency patch v2.4.2 on August 7, 2026 to close the exposure, though already-stolen macaroon files remained valid until operators manually revoked them at the node level. Confirmed victims include hardware wallet company Foundation and Bitcoin publication Citadel21, with total losses undisclosed.

Connected Entities

4 entities · 60 linked investigations
Organizations
BTCPay Server — LND Macaroon Credential Exploit (August 2026)BTCPay Server — Lightning LND Macaroon Exploit (August 2026)
Tokens
Relationships
  • BTCPay Server — LND Macaroon Credential Exploit (August 2026)mentioned withBTCPay Server — Lightning LND Macaroon Exploit (August 2026)(85%)
  • BTCPay Server — LND Macaroon Credential Exploit (August 2026)mentioned withBitcoin(80%)
  • BTCPay Server — Lightning LND Macaroon Exploit (August 2026)mentioned withBitcoin(70%)
  • BTCPay Server — Lightning LND Macaroon Exploit (August 2026)mentioned withCointelegraph(60%)
  • BTCPay Server — Lightning LND Macaroon Exploit (August 2026)mentioned withBTCPay Server — LND Macaroon Credential Exploit (August 2026)(90%)

Connected Through

4 shared actors · 552 investigations

Distinct actors this investigation shares with others — holders, traders, and named parties. Shared infrastructure (exchanges, pools) is excluded.

Have evidence about BTCPay Server — Lightning LND Macaroon Exploit (August 2026)?
0
Accepted
3
Under review
0
Rejected / revoked

Community submissions

Timeline(6 events)

4 August 2026

TOTP two-factor authentication bypass in BTCPay Server Greenfield API reportedly fixed internally (later included in v2.4.2 changelog).

GitHub Release v2.4.2 / CoinDesk reporting

7 August 2026

Bitcoin Red Team (Craig Raw, Rob Hamilton, Calle, Evan Kaloudis) responsibly disclosed the LND macaroon vulnerability to BTCPay Server.

BTCPay Server on X

7 August 2026

BTCPay Server issued public emergency advisory disclosing active exploitation. Foundation and Citadel21 nodes had already been drained before the advisory was published. BTCPay Server v2.4.2 released as emergency patch.

BTCPay Server Blog / CoinDesk

8 August 2026

Multiple major outlets (CoinDesk, CoinTelegraph, Blockonomi, CryptoTimes) published coverage of confirmed thefts from Foundation and Citadel21. Total loss amounts not disclosed by either victim.

CoinDesk

8 August 2026

BTCPay Server confirmed stolen macaroon files remain valid after patching and emphasized mandatory three-step remediation beyond the software update.

CoinTelegraph / TFTC

9 August 2026

Ongoing coverage; no CVE number assigned; technical details of exact exploit path still withheld by BTCPay Server.

CoinTelegraph
Provenance & Audit Trail

Decision Log

This investigation is cryptographically anchored to the Solana blockchain (3 events). 13 of 15 cited source URLs have an Internet Archive snapshot.

model: claude-sonnet-4-6

generated: 8/9/2026, 11:04:17 PM

last updated: 8/25/2026, 7:38:45 PM

4 views

avoid.net — verified advice for a post-truth world