BTCPay Server issued an emergency warning after confirming active exploitation of a critical flaw that allowed attackers to compromise self-hosted payment servers and steal funds from connected LND Lightning nodes. The project told operators to upgrade immediately to BTCPay Server 2.4.2 and NBXplorer 2.6.10, or shut systems down if patching was not possible. Public reports said affected users had channels closed and balances swept, and organizations including Foundation were identified among victims, while the total number of impacted deployments and losses remained unclear.
Reporting tied the issue to BTCPay Server’s Greenfield API authentication flow, where HTTP Basic authentication could bypass two-factor protections for accounts using TOTP without a FIDO2 credential. BTCPay said attackers were able to steal Lightning credentials, including LND macaroons, and warned that patching alone would not invalidate stolen secrets. Operators were instructed to rotate macaroons and related credentials and move funds from hot on-chain wallets created inside BTCPay, while the software was changed to enforce account-level 2FA checks and disable Greenfield Basic authentication by default shortly after account creation unless explicitly enabled.

See which actors are running it and whether you're in range.
8 events from the most recent confirmed update back to the earliest known activity.
BTCPay Server released version 2.4.2 as an emergency fix for a critical vulnerability under active exploitation and told operators to upgrade immediately or shut servers down. The release also instructed integrators to update NBXplorer to version 2.6.10.
BTCPay fixed a Greenfield API bug that allowed HTTP Basic authentication to bypass two-factor authentication for some accounts protected by authenticator apps. The bug was distinct from the later-undisclosed flaw BTCPay said was being actively exploited.
A release-day commit marked nine controller methods across five files as non-routable, removing endpoints that had been accidentally reachable over HTTP. The change was part of the broader security response in version 2.4.2.
As part of its response, BTCPay introduced a breaking change that disables Greenfield Basic authentication by default five minutes after account creation unless explicitly enabled. The project described the change as a measure to reduce the blast radius of future authentication bugs.
BTCPay warned that patching alone was insufficient because stolen credentials could remain valid, and instructed users to rotate LND macaroons and other Lightning authentication strings. It also told users with hot on-chain wallets created inside BTCPay to move funds and recreate those wallets.
Craig Raw of Sparrow Wallet was reportedly affected and analyzed logs, helping identify what was happening during the exploitation campaign. Nicolas Dorier credited Raw with figuring out the issue after the attacks were underway.
Before BTCPay's public alert, attackers compromised vulnerable BTCPay Server instances using LND, stole Lightning credentials, and swept funds from affected nodes. Publicly identified victims included Foundation and Citadel21, with reports of channels being closed and balances drained.
BTCPay Server released a critical security patch for shared or multi-tenant deployments that shared internal Lightning nodes, and urged operators of shared instances to update. The changelog credits @yilakb with reporting the issue.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
8 references tracked. Mallory keeps watching after this page renders.
xakep.ru
Open sourcethecybersecguru.com
Open sourcethedefiant.io
Open sourcegithub.com
Open sourcegithub.com
Open sourceblog.btcpayserver.org
Open sourceblog.btcpayserver.org
Open sourceblog.btcpayserver.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.