Bitcoin infrastructure exploit drains merchant Lightning nodes

1 hour ago 1



BTCPay Server, the open-source payment processor used by thousands of Bitcoin merchants worldwide, issued an urgent security alert on August 7 after attackers exploited a critical vulnerability to drain funds from connected Lightning nodes. The flaw gave unauthorized access to Lightning node credentials, and at least two prominent Bitcoin community members confirmed their nodes were emptied overnight. Foundation, the company behind a popular line of hardware wallets, and hodlonaut, who runs the Bitcoin publication Citadel21, both reported that their Lightning channels were force-closed and funds swept clean. Their associated hot wallets were not affected, which narrows the attack vector to something specific about how BTCPay Server handled Lightning node authentication. What went wrong The vulnerability centered on Lightning node credentials known as macaroons, which function like API keys that grant permission to perform actions on a Lightning node. The problem was that these credentials persisted even after users applied previous software updates. Operators who had dutifully updated their BTCPay Server installations were still exposed because the old macaroons remained valid and ...

Read Entire Article