BTCPay Server — LND Macaroon Credential Exploit (August 2026)
Auto-generated score, not yet verified against the scoring model. Under review — treat as indicative, not a verdict.
anchored·3znFDM…prHCSummary
BTCPay Server is a widely used open-source, self-hosted Bitcoin payment processor created in 2017. On August 7, 2026, the project disclosed and patched a critical pre-authentication vulnerability (present in all versions before 2.4.2) that allowed remote attackers to steal LND macaroon credential files and drain connected merchant Lightning nodes. The vulnerability was actively exploited before the public disclosure, with confirmed victims including hardware wallet maker Foundation and Bitcoin publication Citadel21; the attacker remained unidentified as of mid-August 2026.
Connected Entities
4 entities · 60 linked investigations- Liquid Network→mentioned with→Bitcoin(80%)
- BTCPay Server — LND Macaroon Credential Exploit (August 2026)→mentioned with→Liquid Network(80%)
- BTCPay Server — LND Macaroon Credential Exploit (August 2026)→mentioned with→BTCPay Server — Lightning LND Macaroon Exploit (August 2026)(85%)
- BTCPay Server — LND Macaroon Credential Exploit (August 2026)→mentioned with→Bitcoin(80%)
- BTCPay Server — Lightning LND Macaroon Exploit (August 2026)→mentioned with→Bitcoin(70%)
- BTCPay Server — Lightning LND Macaroon Exploit (August 2026)→mentioned with→BTCPay Server — LND Macaroon Credential Exploit (August 2026)(90%)
Connected Through
4 shared actors · 483 investigationsDistinct actors this investigation shares with others — holders, traders, and named parties. Shared infrastructure (exchanges, pools) is excluded.
- ♦Bitcointoken
- □Liquid Networkorganization
- □BTCPay Server — Lightning LND Macaroon Exploit (August 2026)organization
- □BTCPay Server — LND Macaroon Credential Exploit (August 2026)organization
1 submission awaiting moderator review.
Timeline(6 events)
August 2017
Nicolas Dorier publicly announced BTCPay Server, an open-source self-hosted Bitcoin payment processor, as an alternative to BitPay.
Bitcoin Magazine7 August 2026
BTCPay Server issued an emergency security advisory confirming active exploitation of a critical pre-authentication vulnerability affecting all versions before 2.4.2 that allowed remote attackers to steal LND macaroon credential files. Version 2.4.2 was released the same day.
BTCPay Server Blog (official security advisory)7 August 2026
Foundation (maker of Passport hardware wallets) reported its BTCPay-connected Lightning node was drained overnight; CEO Zach Herbert confirmed attackers closed payment channels and swept funds. Citadel21 also reported its Lightning node was swept.
CoinDesk (August 8, 2026)8 August 2026
CoinDesk reported on the incident, noting victims were compromised before BTCPay's public warning went live.
CoinDesk10 August 2026
BTCPay Server supporters publicly pledged a recovery bounty of 10% of any returned stolen funds, capped at 3 BTC (approximately $190,000), open to anyone including the attacker who provides information leading to fund recovery.
The Block11 August 2026
CoinDesk published a follow-up report on the $190,000 bounty offer. The attacker remained unidentified and no recovery had been announced.
CoinDeskDecision Log
- slot 443511328 · hash 6AUSQqLDZiQNDjQHb2uTFNkz4JEnGvLgbpoKD3xoopL4
- slot 443511280 · hash H63C5pfdUcp2JY7cwwGm4aSdZJWyT5SgYkuWe9QmFKWK
- slot 443509847 · hash EStCvXJvTwH58keRvYnM5wghRya2poWSGmzpfnVujXw6
This investigation is cryptographically anchored to the Solana blockchain (3 decisions). 14 of 15 cited source URLs have an Internet Archive snapshot.
model: claude-sonnet-4-6
generated: 8/22/2026, 11:03:49 PM
last updated: 8/25/2026, 3:27:38 AM
3 viewsavoid.net — verified advice for a post-truth world