BTCPay Server Urges Immediate Update After Critical Exploit
BTCPay Server is a free, open-source, self-hosted Bitcoin payment processor that lets merchants accept on-chain and Lightning Network payments without an intermediary. The incident matters because deployments using LND store .macaroon credentials that can authorize control of a Lightning node. If stolen, those files can let an unauthenticated remote attacker take over the node and transfer funds, exposing the operational risks that accompany self-managed payment infrastructure.
BTCPay Server released version 2.4.2 on Aug. 7, 2026, saying every earlier version, including release candidates, contained the flaw and confirming that attackers had stolen funds from users. LND operators were told to upgrade immediately, verify LND 0.21.1, review balances and unauthorized activity, or take affected servers offline. The project temporarily disabled public LND API access on Docker deployments, while supporters offered a recovery bounty of as much as 3 BTC on Aug. 11. Total losses and the number of victims remain undisclosed.
All Coverage
9 original reportsThe Backstory
The history behind this eventNo historical echoes for this signal
Subscribe to Mark Radar Weekly
Every Friday, the week's strongest signals in your inbox. Unsubscribe anytime.