Close Menu
    Facebook X (Twitter) Instagram
    • Privacy Policy
    • Terms Of Service
    • Social Media Disclaimer
    • DMCA Compliance
    • Anti-Spam Policy
    Facebook X (Twitter) Instagram
    Bytecore News
    • Home
    • Crypto News
      • Bitcoin
      • Ethereum
      • Altcoins
      • Blockchain
      • DeFi
    • AI News
    • Stock News
    • Learn
      • AI for Beginners
      • AI Tips
      • Make Money with AI
    • Reviews
    • Tools
      • Best AI Tools
      • Crypto Market Cap List
      • Stock Market Overview
      • Market Heatmap
    • Contact
    Bytecore News
    Home»Crypto News»Bitcoin»BTCPay Server Rotates Credentials After Lightning Exploit
    Cointelegraph
    Bitcoin

    BTCPay Server Rotates Credentials After Lightning Exploit

    August 9, 20262 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email
    murf



    BTCPay Server has temporarily restricted public remote connections to Lightning Network nodes running Lightning Network Daemon (LND) software after attackers exploited a critical vulnerability to obtain credentials and move funds. 

    BTCPay said the restriction prevents external wallets such as Zeus from connecting through a BTCPay Server domain or Tor onion address on Docker deployments. BTCPay said Lightning payments can continue and that it plans to restore the remote-access option when it considers it safe. 

    Version 2.4.2 installs LND version 0.21.1 and automatically regenerates the macaroon credentials on standard BTCPay installations. The project advised operators to check for unauthorized payments, unexpected channel closures, unfamiliar peers and discrepancies in their onchain or Lightning balances.

    The BTCPay breach is the latest security incident involving widely used Bitcoin products, following a Coldcard hardware-wallet flaw linked to more than $100 million in confirmed losses. The separate incidents affected software surrounding Bitcoin rather than the network’s underlying protocol.

    binance

    Update automatically rotates Lightning credentials

    BTCPay said the vulnerability allowed an unauthenticated remote attacker to obtain “macaroon” credential files used to control LND, an implementation of the Lightning Network. The project said the exposed credentials could allow attackers to take control of an LND node and move its funds.

    According to the project’s security advisory, version 2.4.2 installs LND version 0.21.1 and automatically regenerates macaroon credentials on standard BTCPay installations. It advised operators to check for unauthorized payments, unexpected channel closures, unfamiliar peers and discrepancies between their records and onchain or Lightning balances. 

    Related: Coldcard exploit pushes July losses to $247M as second-worst month of 2026

    BTCPay also said operators exposing LND through their own reverse proxy, Tor service, forwarded port, or another route outside BTCPay must rotate their credentials separately. The project said installing the update does not close access routes managed independently by the operator. 

    At least two operators publicly reported losses. Foundation CEO Zach Herbert said the hardware-wallet company’s Lightning node was drained overnight. He later clarified that its hot wallet was unaffected, while its Lightning channels were closed and the funds swept. 

    Bitcoin publication Citadel21 also reported that its Lightning node had been swept. Neither operator disclosed the amount lost. 

    Magazine: 10 weirdest things ever tokenized… including farts

    Cointelegraph is committed to independent, transparent journalism. This news article is produced in accordance with Cointelegraph’s Editorial Policy and aims to provide accurate and timely information. Readers are encouraged to verify information independently.



    Source link

    synthesia
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    CryptoExpert
    • Website

    Related Posts

    Moreno Signals End to Clarity Act Talks Ahead of Cloture Vote

    August 8, 2026

    Bitcoin Barely Budges as Weak US Jobs Data Cuts Fed Hike Odds to 44%

    August 8, 2026

    US Nonfarm Payrolls Miss Sends Bitcoin Above $65,000

    August 7, 2026

    Coldcard Hacker Resumes Moving Stolen 30 BTC to New Wallet

    August 7, 2026
    Add A Comment
    Leave A Reply Cancel Reply

    kraken
    Latest Posts

    Meet Shepherd: An Open-Source Python Substrate That Lets Meta-Agents Fork, Replay, and Revert Any Agent Run

    August 8, 2026

    Laziest Way to Make Money with AI Today (NO SKILLS)

    August 8, 2026

    DONT LEARN AI BEFORE WATCHING THIS

    August 8, 2026

    Moreno Signals End to Clarity Act Talks Ahead of Cloture Vote

    August 8, 2026

    Bitcoin Barely Budges as Weak US Jobs Data Cuts Fed Hike Odds to 44%

    August 8, 2026
    changelly
    LEGAL INFORMATION
    • Privacy Policy
    • Terms Of Service
    • Social Media Disclaimer
    • DMCA Compliance
    • Anti-Spam Policy
    Top Insights

    BTCPay Server Rotates Credentials After Lightning Exploit

    August 9, 2026

    Recent Binance Updates, Top SOL and DOGE Forecasts, and More: Bits Recap August 7

    August 9, 2026
    notion
    Facebook X (Twitter) Instagram Pinterest
    © 2026 BytecoreNews.com - All rights reserved.

    Type above and press Enter to search. Press Esc to cancel.