Skip to main content
Sign in

BTCPay Server — LND Macaroon Credential Exploit (August 2026)

avoid.net/btcpay-server-lnd-macaroon-credential-exploit-august-202652/100·82% conf.
[VERIFIED]

Auto-generated score, not yet verified against the scoring model. Under review — treat as indicative, not a verdict.

anchored·3znFDM…prHC

Summary

BTCPay Server is a widely used open-source, self-hosted Bitcoin payment processor created in 2017. On August 7, 2026, the project disclosed and patched a critical pre-authentication vulnerability (present in all versions before 2.4.2) that allowed remote attackers to steal LND macaroon credential files and drain connected merchant Lightning nodes. The vulnerability was actively exploited before the public disclosure, with confirmed victims including hardware wallet maker Foundation and Bitcoin publication Citadel21; the attacker remained unidentified as of mid-August 2026.

Connected Entities

1 entities
Organizations
BTCPay Server — LND Macaroon Credential Exploit (August 2026)
Relationships
    Have evidence about BTCPay Server — LND Macaroon Credential Exploit (August 2026)?
    0
    Accepted
    1
    Under review
    0
    Rejected / revoked

    Community submissions

    Timeline(6 events)

    August 2017

    Nicolas Dorier publicly announced BTCPay Server, an open-source self-hosted Bitcoin payment processor, as an alternative to BitPay.

    Bitcoin Magazine

    7 August 2026

    BTCPay Server issued an emergency security advisory confirming active exploitation of a critical pre-authentication vulnerability affecting all versions before 2.4.2 that allowed remote attackers to steal LND macaroon credential files. Version 2.4.2 was released the same day.

    BTCPay Server Blog (official security advisory)

    7 August 2026

    Foundation (maker of Passport hardware wallets) reported its BTCPay-connected Lightning node was drained overnight; CEO Zach Herbert confirmed attackers closed payment channels and swept funds. Citadel21 also reported its Lightning node was swept.

    CoinDesk (August 8, 2026)

    8 August 2026

    CoinDesk reported on the incident, noting victims were compromised before BTCPay's public warning went live.

    CoinDesk

    10 August 2026

    BTCPay Server supporters publicly pledged a recovery bounty of 10% of any returned stolen funds, capped at 3 BTC (approximately $190,000), open to anyone including the attacker who provides information leading to fund recovery.

    The Block

    11 August 2026

    CoinDesk published a follow-up report on the $190,000 bounty offer. The attacker remained unidentified and no recovery had been announced.

    CoinDesk
    Provenance & Audit Trail

    Decision Log

    This investigation is cryptographically anchored to the Solana blockchain (3 events). 14 of 15 cited source URLs have an Internet Archive snapshot.

    model: claude-sonnet-4-6

    generated: 8/22/2026, 11:03:49 PM

    last updated: 8/25/2026, 3:27:38 AM

    3 views

    avoid.net — verified advice for a post-truth world