๐Ÿ“… Rabu, 12 Agustus 2026 ยท --:-- WIB Ikuti kami
Ecosystem โ–ผ
ID โ–ผ
File Kredensial BTCPay Dicuri Peretas - Node Lightning Foundation dan Citadel21 Dikuras Habis

BTCPay Credential Files Stolen by Hackers - Foundation and Citadel21 Lightning Nodes Drained

An unauthenticated attacker exploited a critical vulnerability in BTCPay Server to steal “.macaroon” credential files, taking over LND Lightning Network nodes and transferring all funds within them.

By the time a public warning was issued, the hackers had already made their move on active servers. Foundation, the creator of Bitcoin hardware wallets, was among the victims. Foundation CEO Zach Herbert confirmed that their BTCPay Lightning node was drained overnight. The attacker forced closed channels and swept all funds, although Foundation’s on-chain hot wallet was confirmed to be secure. The Bitcoin publication owned by pseudonymous figure hodlonaut, Citadel21, also stated that their Lightning node had been completely drained.

To date, the total amount of lost funds and the exact number of affected node operators have not been disclosed.

Report Received Before the Attack Occurred

This incident was actually detected earlier. A developer group named Bitcoin Red Team - which is currently targeting AI models at the Bitcoin codebase - had reported this vulnerability to BTCPay before the exploit occurred. The findings were responsibly submitted by Craig Raw, Rob Hamilton, Calle, and Evan Kaloudis.

Nonetheless, the hackers moved faster than the patch release schedule. This marks the second major security blow to hit Bitcoin infrastructure recently, following an attack on Coldcard hardware wallets that triggered losses exceeding $100 million. BTCPay has not yet disclosed technical details regarding the vulnerability, but they promised a full post-mortem report in the coming days.

Emergency Actions and Access Restrictions

As a mitigation step, BTCPay Server launched patch version 2.4.2. This update installs LND software version 0.21.1 and triggers a regeneration of macaroon credentials on standard installations. They also restricted public remote connections to the LND node. As a result, third-party wallets like Zeus can no longer connect via the BTCPay domain or the Tor network, although Lightning payment functionality remains operational.

Additional warnings apply to operators who expose standalone LND nodes via a reverse proxy, port forwarding, or Tor. The system update does not automatically patch the vulnerability for them. Operators in this category must perform a manual credential rotation to secure their systems again.

This exploit proves that hackers are always lurking to sweep the balances of Lightning channels. For standalone node operators, delaying update instructions and key rotation means handing access to the vault over to the attackers.

Reported by Cointelegraph.


Disclaimer: This article is for informational and educational purposes only, not financial advice. Cryptocurrency assets are highly volatile and carry significant risk. Always do your own research (DYOR) and never invest more than you can afford to lose.

Bagikan artikel ini:
๐Ÿ“ฉ KABAR BITCOIN 1 MENIT

Berita kripto harian, langsung ke inbox

Ringkasan 1 menit untuk kamu yang selalu bergerak. Gratis, kapan saja bisa berhenti.

Total
0
Share