On August 7, 2026, BTCPay Server warned users of an actively exploited critical vulnerability that allows attackers to drain funds from Lightning nodes. Because the software is self-hosted, merchants must manually update to version 2.4.2 or shut down their servers. Victims including Foundation and Citadel21 reported node drains prior to the public alert. The bug was discovered by Sparrow Wallet developer Craig Raw after losing funds, bypassing recent AI-assisted audits by the Bitcoin Red Team.
Story comments
Loading comments…