← BTCPay Server — Lightning LND Macaroon Exploit (August 2026)1 decision on this page
Audit log
Every state-changing event for BTCPay Server — Lightning LND Macaroon Exploit (August 2026): moderation decisions on community submissions, plus corrections and updates from the news pipeline. URL-based decisions are designed to carry three independent witnesses — the original source, an Internet Archive snapshot, and a Solana memo signed by our publicly-disclosed publisher key. Archive coverage is still being backfilled, so each decision below reports its own snapshot status rather than assuming one exists.
- #1publishby system:backfill2026-08-09 23:04:26ZScore: ? → ? (no score change)anchorpending
- chain
- ●—
- hash
BDxFUiJTw6wC…veLNsRLcsha256 → base58
verifying row…canonical bytes (19287 B) ▸
{"actor":"system:backfill","investigation_id":"78b38f72-39bb-4310-8c4f-1c0987620b7a","kind":"publish","page_slug":"btcpay-server-lightning-lnd-macaroon-exploit-august-2026","published_at":"2026-08-09T23:04:26.796Z","sequence_num":1,"snapshot":{"content_type":"investigation","entity_name":"BTCPay Server — Lightning LND Macaroon Exploit (August 2026)","sections":[{"content":"BTCPay Server confirmed on August 7, 2026 that a critical security flaw was being actively exploited against live deployments. The vulnerability allowed an unauthenticated remote attacker to obtain .macaroon credential files from BTCPay Server instances running LND (Lightning Network Daemon) as their Lightning backend. Macaroons are cryptographic bearer tokens that grant software the authority to interact with an LND node — including opening and closing payment channels and moving funds. An attacker in possession of the admin macaroon gains full control over the associated Lightning node without further authentication. The BTCPay Server team explicitly confirmed that 'attackers exploited this vulnerability. Users were affected and funds were stolen.' The root cause centers on the TOTP two-factor authentication bypass in BTCPay's Greenfield API: when an account was secured by an authenticator app, the API code incorrectly checked for the presence of a FIDO2 hardware key rather than verifying whether any form of 2FA was active. Because most users relying on TOTP had no FIDO2 key registered, the API silently skipped the second factor, permitting login with only an email address and password. This authentication bypass provided access to the server's LND macaroon files. BTCPay developers were explicit that this actively exploited macaroon issue is distinct from — though related to — a separately listed TOTP bypass fix also included in v2.4.2. Technical details of the precise exposure mechanism were intentionally withheld by the project while operators remained on vulnerable versions.","heading":"Vulnerability Overview","severity":"critical","sources":[{"credibility":1,"name":"Security Advisory: Update BTCPay Server to 2.4.2 Immediately | BTCPay Server Blog","type":"official","url":"https://blog.btcpayserver.org/security-advisory-btcpay-server-2-4-2/"},{"credibility":2,"name":"BTCPay Server v2.4.2 Patches Live LND Macaroon Exploit Draining Lightning Nodes — TFTC","type":"news_article","url":"https://www.tftc.io/btcpay-server-v2-4-2-lnd-macaroon-exploit-lightning-nodes-drained"},{"credibility":1,"name":"Another Bitcoin infrastructure exploit hits, this time draining merchant Lightning nodes — CoinDesk","type":"news_article","url":"https://www.coindesk.com/tech/2026/08/08/another-bitcoin-infrastructure-exploit-hits-this-time-draining-merchant-lightning-nodes"},{"credibility":1,"name":"Release v2.4.2 — btcpayserver/btcpayserver on GitHub","type":"official","url":"https://github.com/btcpayserver/btcpayserver/releases/tag/v2.4.2"}]},{"content":"All versions of BTCPay Server prior to v2.4.2 are affected, including v2.4.2 release candidates. The vulnerability is specific to deployments using LND as the Lightning Network backend; BTCPay Server installations using CLN (Core Lightning) or other Lightning implementations are not affected by the macaroon exposure. On-chain wallets held within BTCPay Server are separately noted to be at risk if the attacker also obtained Greenfield API access, and operators were advised to move funds from BTCPay-generated hot wallets and recreate them. LND 0.21.1, bundled with the v2.4.2 update, is required alongside the BTCPay Server patch for Docker-based deployments. Operators using independently managed access routes such as reverse proxies, Tor hidden services, or forwarded ports must manually rotate macaroon credentials, as those external paths are not automatically closed by the BTCPay update alone.","heading":"Affected Versions and Scope","severity":"critical","sources":[{"credibility":1,"name":"Security Advisory: Update BTCPay Server to 2.4.2 Immediately | BTCPay Server Blog","type":"official","url":"https://blog.btcpayserver.org/security-advisory-btcpay-server-2-4-2/"},{"credibility":1,"name":"BTCPay Server Rotates Credentials After Lightning Exploit — CoinTelegraph","type":"news_article","url":"https://cointelegraph.com/news/btcpay-restricts-remote-lightning-access-after-attackers-steal-funds"},{"credibility":2,"name":"BTCPay Server Warns of Critical Flaw That Risks Bitcoin Funds — CryptoTimes","type":"news_article","url":"https://www.cryptotimes.io/2026/08/08/btcpay-server-warns-of-critical-flaw-that-risks-bitcoin-funds/"}]},{"content":"The vulnerability was already being actively exploited when BTCPay Server issued its public advisory on August 7, 2026. Two organizations publicly confirmed their Lightning nodes were drained before the advisory went live. Foundation, the company behind the Passport hardware wallet, had its BTCPay Lightning node closed and swept overnight, with CEO Zach Herbert publicly confirming the theft. Foundation noted that its on-chain hot wallet was not compromised. Citadel21, a Bitcoin-focused publication associated with pseudonymous commentator hodlonaut, also reported its Lightning node was drained, though it noted minimal funds were held there at the time. Total amounts stolen by Foundation, Citadel21, or other unidentified victims have not been publicly disclosed. BTCPay Server confirmed that users were affected and funds were stolen but declined to specify the total number of compromised installations or the aggregate value of losses. The vulnerability was discovered and reported to BTCPay Server by members of the Bitcoin Red Team, a group that included Craig Raw (Sparrow Wallet), Rob Hamilton, Calle, and Evan Kaloudis, who provided details to assist in addressing the issue.","heading":"Active Exploitation and Confirmed Victims","severity":"critical","sources":[{"credibility":1,"name":"Another Bitcoin infrastructure exploit hits, this time draining merchant Lightning nodes — CoinDesk","type":"news_article","url":"https://www.coindesk.com/tech/2026/08/08/another-bitcoin-infrastructure-exploit-hits-this-time-draining-merchant-lightning-nodes"},{"credibility":2,"name":"Critical BTCPay Server Vulnerability Leads to Lightning Network Node Thefts — Blockonomi","type":"news_article","url":"https://blockonomi.com/critical-btcpay-server-vulnerability-leads-to-lightning-network-node-thefts"},{"credibility":2,"name":"BTCPay Server on X — disclosure credit to Bitcoin Red Team","type":"social_media","url":"https://x.com/BtcpayServer/status/2085771939008667869"},{"credibility":2,"name":"Hackers Exploit BTCPay Vulnerability to Drain Lightning Nodes — ForkLog","type":"news_article","url":"https://forklog.com/en/hackers-exploit-btcpay-vulnerability-to-drain-lightning-nodes/"}]},{"content":"BTCPay Server released v2.4.2 on August 7, 2026 as an emergency patch. The release disables basic authentication by default five minutes after account creation and fixes the TOTP 2FA bypass in the Greenfield API. For Docker deployments, the update also installs LND 0.21.1 and automatically regenerates macaroon credentials. The BTCPay Server team advised any operator who could not immediately patch to take their server offline until the update could be applied. Critically, patching alone is insufficient for operators whose server was running a vulnerable version prior to the update. The project and multiple security analysts emphasized a three-step remediation: (1) update BTCPay Server to v2.4.2 and LND to v0.21.1; (2) revoke and regenerate all LND macaroon credentials at the node level by deleting the macaroons.db root signing key file and restarting LND, not merely deleting the credential files; and (3) move all Bitcoin from any BTCPay-generated on-chain hot wallet to a fresh wallet, then recreate the hot wallet within BTCPay. Operators who updated but skipped credential regeneration or wallet migration remained at risk from previously stolen macaroon files, which do not expire and are not invalidated by the software update alone. The project also temporarily restricted LND API public access on Docker deployments as an additional protective measure.","heading":"Patch and Remediation","severity":"high","sources":[{"credibility":1,"name":"Security Advisory: Update BTCPay Server to 2.4.2 Immediately | BTCPay Server Blog","type":"official","url":"https://blog.btcpayserver.org/security-advisory-btcpay-server-2-4-2/"},{"credibility":2,"name":"BTCPay Server v2.4.2 Patches Live LND Macaroon Exploit Draining Lightning Nodes — TFTC","type":"news_article","url":"https://www.tftc.io/btcpay-server-v2-4-2-lnd-macaroon-exploit-lightning-nodes-drained"},{"credibility":1,"name":"Release v2.4.2 — btcpayserver/btcpayserver on GitHub","type":"official","url":"https://github.com/btcpayserver/btcpayserver/releases/tag/v2.4.2"},{"credibility":1,"name":"BTCPay Server Rotates Credentials After Lightning Exploit — CoinTelegraph","type":"news_article","url":"https://cointelegraph.com/news/btcpay-restricts-remote-lightning-access-after-attackers-steal-funds"}]},{"content":"LND (Lightning Network Daemon), developed by Lightning Labs, authenticates API requests using macaroon files — cryptographic bearer credentials analogous to API keys with scoped permissions. LND generates three default macaroon types at startup: an admin macaroon granting full node control, a read-only macaroon, and an invoice macaroon for generating payment requests. Bearer credentials of this type carry an inherent risk: any party possessing the file gains the associated permissions with no further identity verification. BTCPay Server stores and uses these macaroon files to communicate with a merchant's LND node on their behalf. The vulnerability enabled an unauthenticated attacker to retrieve the admin macaroon, granting them the same level of access as the node operator. This permitted forced channel closures and fund sweeps from Lightning payment channels. The incident highlighted a structural risk in self-hosted payment infrastructure: the combination of internet-exposed BTCPay instances with local LND nodes creates an attack surface that, if the application layer is compromised, gives attackers direct access to custodied funds. The exploit did not affect the Bitcoin base layer, on-chain UTXO security at the protocol level, or BTCPay users running non-LND Lightning backends such as CLN.","heading":"LND Macaroon Architecture and Risk Context","severity":"medium","sources":[{"credibility":2,"name":"BTCPay Server v2.4.2 Patches Live LND Macaroon Exploit Draining Lightning Nodes — TFTC","type":"news_article","url":"https://www.tftc.io/btcpay-server-v2-4-2-lnd-macaroon-exploit-lightning-nodes-drained"},{"credibility":2,"name":"BTCPay Lightning Nodes Drained in Live Attack as Operators Rush to Patch LND Servers — Bitzo","type":"news_article","url":"https://bitzo.com/2026/08/btcpay-lightning-nodes-drained-patch-lnd"},{"credibility":2,"name":"BTCPay emergency patch exposes merchant-side Bitcoin security risk — Cryptopolitan","type":"news_article","url":"https://www.cryptopolitan.com/btcpay-emergency-patch-exposes-merchant-side-bitcoin-security-risk/"}]},{"content":"The Bitcoin Red Team — comprising Craig Raw (Sparrow Wallet developer), Rob Hamilton, Calle, and Evan Kaloudis — is credited with responsibly disclosing the vulnerability to BTCPay Server and providing details that enabled the patch. BTCPay Server acknowledged the disclosure publicly via its official X (Twitter) account. Despite responsible disclosure practices, exploitation was already underway against live servers by the time the public advisory was issued on August 7, 2026, suggesting the vulnerability was independently discovered and weaponized prior to or simultaneously with the Red Team's notification. BTCPay Server is an open-source, non-custodial self-hosted payment processor and did not take custody of affected funds directly. The project did not disclose whether it had received prior reports of the vulnerability from other parties or the precise interval between exploitation onset and patch release. No CVE identifier had been assigned as of the date of reporting. Technical specifics of the exploit mechanism beyond the TOTP API bypass were withheld by BTCPay Server during the active exploitation window, which is consistent with standard coordinated disclosure practice.","heading":"Disclosure and Project Response","severity":"medium","sources":[{"credibility":2,"name":"BTCPay Server on X — active exploitation advisory","type":"social_media","url":"https://x.com/BtcpayServer/status/2085755643659522240"},{"credibility":2,"name":"BTCPay Server on X — disclosure credit to Bitcoin Red Team","type":"social_media","url":"https://x.com/BtcpayServer/status/2085771939008667869"},{"credibility":3,"name":"BTCPay Server Issues Critical Security Alert: Update to Version 2.4.2 Immediately or Go Offline — Glitchwire","type":"news_article","url":"https://glitchwire.com/news/btcpay-server-issues-critical-security-alert-update-to-version-242-immediately-o/"},{"credibility":1,"name":"BTC news: Bitcoin's exploit week worsens as BTCPay flaw drains Lightning nodes — CoinDesk","type":"news_article","url":"https://www.coindesk.com/tech/2026/08/08/another-bitcoin-infrastructure-exploit-hits-this-time-draining-merchant-lightning-nodes"}]}],"sources_used":[{"credibility":1,"name":"Security Advisory: Update BTCPay Server to 2.4.2 Immediately | BTCPay Server Blog","type":"official","url":"https://blog.btcpayserver.org/security-advisory-btcpay-server-2-4-2/"},{"credibility":1,"name":"Release v2.4.2 — btcpayserver/btcpayserver on GitHub","type":"official","url":"https://github.com/btcpayserver/btcpayserver/releases/tag/v2.4.2"},{"credibility":1,"name":"Another Bitcoin infrastructure exploit hits, this time draining merchant Lightning nodes — CoinDesk","type":"news_article","url":"https://www.coindesk.com/tech/2026/08/08/another-bitcoin-infrastructure-exploit-hits-this-time-draining-merchant-lightning-nodes"},{"credibility":1,"name":"BTCPay Server Rotates Credentials After Lightning Exploit — CoinTelegraph","type":"news_article","url":"https://cointelegraph.com/news/btcpay-restricts-remote-lightning-access-after-attackers-steal-funds"},{"credibility":2,"name":"BTCPay Server v2.4.2 Patches Live LND Macaroon Exploit Draining Lightning Nodes — TFTC","type":"news_article","url":"https://www.tftc.io/btcpay-server-v2-4-2-lnd-macaroon-exploit-lightning-nodes-drained"},{"credibility":2,"name":"Critical BTCPay Server Vulnerability Leads to Lightning Network Node Thefts — Blockonomi","type":"news_article","url":"https://blockonomi.com/critical-btcpay-server-vulnerability-leads-to-lightning-network-node-thefts"},{"credibility":2,"name":"BTCPay Server Warns of Critical Flaw That Risks Bitcoin Funds — CryptoTimes","type":"news_article","url":"https://www.cryptotimes.io/2026/08/08/btcpay-server-warns-of-critical-flaw-that-risks-bitcoin-funds/"},{"credibility":2,"name":"BTCPay emergency patch exposes merchant-side Bitcoin security risk — Cryptopolitan","type":"news_article","url":"https://www.cryptopolitan.com/btcpay-emergency-patch-exposes-merchant-side-bitcoin-security-risk/"},{"credibility":2,"name":"Hackers Exploit BTCPay Vulnerability to Drain Lightning Nodes — ForkLog","type":"news_article","url":"https://forklog.com/en/hackers-exploit-btcpay-vulnerability-to-drain-lightning-nodes/"},{"credibility":2,"name":"BTCPay Lightning Nodes Drained in Live Attack as Operators Rush to Patch LND Servers — Bitzo","type":"news_article","url":"https://bitzo.com/2026/08/btcpay-lightning-nodes-drained-patch-lnd"},{"credibility":2,"name":"BTCPay Server on X — active exploitation advisory","type":"social_media","url":"https://x.com/BtcpayServer/status/2085755643659522240"},{"credibility":2,"name":"BTCPay Server on X — disclosure credit to Bitcoin Red Team","type":"social_media","url":"https://x.com/BtcpayServer/status/2085771939008667869"},{"credibility":2,"name":"Bitcoin Lightning Nodes Hit as BTCPay Signals Emergency 2.4.2 Fix — Bitcoin.com News","type":"news_article","url":"https://news.bitcoin.com/security/bitcoin-lightning-nodes-hit-as-btcpay-signals-emergency-2-4-2-fix/"},{"credibility":2,"name":"Lightning Nodes Drained As BTCPay Server Users Race To Patch — The Defiant","type":"news_article","url":"https://thedefiant.io/news/hacks/btcpay-server-tells-operators-to-update-or-shut-down-over-actively-exploited-flaw"},{"credibility":2,"name":"BTCPay Server Suspends Lightning Node Remote Access Following Security Breach — Blockonomi","type":"news_article","url":"https://blockonomi.com/btcpay-server-suspends-lightning-node-remote-access-following-security-breach"}],"summary":"In August 2026, a critical, actively exploited vulnerability in BTCPay Server allowed unauthenticated remote attackers to obtain LND macaroon credential files, granting full administrative access to victim Lightning nodes and enabling fund theft. BTCPay Server released emergency patch v2.4.2 on August 7, 2026 to close the exposure, though already-stolen macaroon files remained valid until operators manually revoked them at the node level. Confirmed victims include hardware wallet company Foundation and Bitcoin publication Citadel21, with total losses undisclosed.","timeline":[{"date":"2026-08-04","event":"TOTP two-factor authentication bypass in BTCPay Server Greenfield API reportedly fixed internally (later included in v2.4.2 changelog).","source":"GitHub Release v2.4.2 / CoinDesk reporting","source_url":"https://github.com/btcpayserver/btcpayserver/releases/tag/v2.4.2"},{"date":"2026-08-07","event":"Bitcoin Red Team (Craig Raw, Rob Hamilton, Calle, Evan Kaloudis) responsibly disclosed the LND macaroon vulnerability to BTCPay Server.","source":"BTCPay Server on X","source_url":"https://x.com/BtcpayServer/status/2085771939008667869"},{"date":"2026-08-07","event":"BTCPay Server issued public emergency advisory disclosing active exploitation. Foundation and Citadel21 nodes had already been drained before the advisory was published. BTCPay Server v2.4.2 released as emergency patch.","source":"BTCPay Server Blog / CoinDesk","source_url":"https://blog.btcpayserver.org/security-advisory-btcpay-server-2-4-2/"},{"date":"2026-08-08","event":"Multiple major outlets (CoinDesk, CoinTelegraph, Blockonomi, CryptoTimes) published coverage of confirmed thefts from Foundation and Citadel21. Total loss amounts not disclosed by either victim.","source":"CoinDesk","source_url":"https://www.coindesk.com/tech/2026/08/08/another-bitcoin-infrastructure-exploit-hits-this-time-draining-merchant-lightning-nodes"},{"date":"2026-08-08","event":"BTCPay Server confirmed stolen macaroon files remain valid after patching and emphasized mandatory three-step remediation beyond the software update.","source":"CoinTelegraph / TFTC","source_url":"https://cointelegraph.com/news/btcpay-restricts-remote-lightning-access-after-attackers-steal-funds"},{"date":"2026-08-09","event":"Ongoing coverage; no CVE number assigned; technical details of exact exploit path still withheld by BTCPay Server.","source":"CoinTelegraph","source_url":"https://cointelegraph.com/news/btcpay-restricts-remote-lightning-access-after-attackers-steal-funds"}]},"v":1}Verify offline (run on your own machine)python -m src.verify_decision a5c00c86-9319-4cdf-a98f-4c63a8d875f0
How verification works. The “Row integrity” check above is computed in your browser — your machine recomputes the SHA-256 of the canonical bytes and compares against the stored hash. No avoid.net server can fake that check. The “full verify” link goes one level deeper: your browser fetches the on-chain transaction from a Solana RPC node and confirms the same hash is in the memo. If you don’t want to trust either avoid.net or the public RPC, run the CLI verifier on your own machine —
python -m src.verify_decision <event_id>.