BTCPay Server Critical Flaw Allowed Fund Theft From Lightning Nodes; Patch Released
BTCPay Server has disclosed a critical security vulnerability that allowed attackers to steal funds from Lightning Network nodes. The flaw affected all versions prior to 2.4.2 and permitted unauthenticated access. Version 2.4.2 has been released to patch the vulnerability.
BTCPay Server Critical Flaw Allowed Fund Theft From Lightning Nodes; Patch Released
BTCPay Server has disclosed a critical security vulnerability that allowed attackers to steal funds from Lightning Network nodes, urging all operators to update to version 2.4.2 immediately.
The vulnerability affected every version of BTCPay Server prior to 2.4.2 and permitted unauthenticated access, meaning attackers did not need valid credentials to exploit the flaw. BTCPay Foundation and payment infrastructure provider Citadel21 both reported drained Lightning nodes following active exploitation. The total amount stolen and the precise number of affected operators remain unknown.
"BTCPay Server confirmed that attackers exploited a critical flaw to steal funds from users running any version prior to 2.4.2 and urged operators to update immediately."
BTCPay Server, official statement
BTCPay Server is a self-hosted, open-source Bitcoin payment processor used by merchants, developers, and nonprofits worldwide. Because it is self-hosted, each operator runs their own instance rather than relying on a shared platform, which limits blast radius but also means patching responsibility falls entirely on individual operators. Lightning Network nodes, which BTCPay integrates to enable near-instant, low-fee Bitcoin payments, hold live funds in payment channels, making them an attractive target when exposed through a software flaw.
The BTCPay team released version 2.4.2 shortly after confirming active exploitation, following a responsible disclosure model that prioritizes getting a patch out before publishing full technical details. That sequencing is standard practice in open-source security and reduces the window for opportunistic attackers who scan for unpatched instances once a vulnerability becomes public. Operators who have not yet updated remain exposed.
Lightning node security is operationally distinct from Bitcoin base-layer security. A vulnerability in payment software does not touch Bitcoin's consensus mechanism or the underlying blockchain. Funds held in Lightning channels, however, are hot by design: they must be online and accessible to route payments, which means any software flaw in the node's management interface can have direct financial consequences. This attack vector, unauthenticated remote access to a node, ranks among the most severe because it requires no prior foothold on the target system.
Unpatched software becomes a target quickly once a flaw is discovered, and losses concentrate among operators slow to apply updates. The BTCPay Foundation's transparency in disclosing the incident publicly, rather than quietly pushing a patch, gives the broader operator community the context needed to assess their own exposure.
Any operator running BTCPay Server on a version below 2.4.2 should treat the update as urgent. The patch is available now through the project's official channels. Given that the total stolen remains unquantified and exploitation was confirmed as active, the window for additional losses is open for anyone still running an older version.





