BTCPay Server — LND Macaroon Credential Exploit (August 2026)
Auto-generated score, not yet verified against the scoring model. Under review — treat as indicative, not a verdict.
anchored·3znFDM…prHCSummary
BTCPay Server is a widely used open-source, self-hosted Bitcoin payment processor created in 2017. On August 7, 2026, the project disclosed and patched a critical pre-authentication vulnerability (present in all versions before 2.4.2) that allowed remote attackers to steal LND macaroon credential files and drain connected merchant Lightning nodes. The vulnerability was actively exploited before the public disclosure, with confirmed victims including hardware wallet maker Foundation and Bitcoin publication Citadel21; the attacker remained unidentified as of mid-August 2026.
Connected Entities
1 entitiesCommunity submissions
- Under reviewincriminatingWayback pending8/29/2026, 11:14:15 AM
“CoinDesk confirms active exploitation of BTCPay Server LND credential flaw; $190K bounty offered; named victims include Foundation hardware wallet maker”
— avoid-scout
Timeline(6 events)
August 2017
Nicolas Dorier publicly announced BTCPay Server, an open-source self-hosted Bitcoin payment processor, as an alternative to BitPay.
Bitcoin Magazine7 August 2026
BTCPay Server issued an emergency security advisory confirming active exploitation of a critical pre-authentication vulnerability affecting all versions before 2.4.2 that allowed remote attackers to steal LND macaroon credential files. Version 2.4.2 was released the same day.
BTCPay Server Blog (official security advisory)7 August 2026
Foundation (maker of Passport hardware wallets) reported its BTCPay-connected Lightning node was drained overnight; CEO Zach Herbert confirmed attackers closed payment channels and swept funds. Citadel21 also reported its Lightning node was swept.
CoinDesk (August 8, 2026)8 August 2026
CoinDesk reported on the incident, noting victims were compromised before BTCPay's public warning went live.
CoinDesk10 August 2026
BTCPay Server supporters publicly pledged a recovery bounty of 10% of any returned stolen funds, capped at 3 BTC (approximately $190,000), open to anyone including the attacker who provides information leading to fund recovery.
The Block11 August 2026
CoinDesk published a follow-up report on the $190,000 bounty offer. The attacker remained unidentified and no recovery had been announced.
CoinDeskDecision Log
- hash: 6AUSQqLDZiQNDjQHb2uTFNkz4JEnGvLgbpoKD3xoopL4
- hash: H63C5pfdUcp2JY7cwwGm4aSdZJWyT5SgYkuWe9QmFKWK
- hash: EStCvXJvTwH58keRvYnM5wghRya2poWSGmzpfnVujXw6
This investigation is cryptographically anchored to the Solana blockchain (3 events). 14 of 15 cited source URLs have an Internet Archive snapshot.
model: claude-sonnet-4-6
generated: 8/22/2026, 11:03:49 PM
last updated: 8/25/2026, 3:27:38 AM
3 viewsavoid.net — verified advice for a post-truth world