On August 7, 2026, BTCPay Server warned users of an actively exploited critical vulnerability that allows attackers to drain funds from Lightning nodes. Because the software is self-hosted, merchants must manually update to version 2.4.2 or shut down their servers. Victims including Foundation and Citadel21 reported node drains prior to the public alert. The bug was discovered by Sparrow Wallet developer Craig Raw after losing funds, bypassing recent AI-assisted audits by the Bitcoin Red Team.
BTCPay Server critical vulnerability
- ▪BTCPay Server urged administrators to update their servers to version 2.4.2 or turn off their servers immediately to prevent unauthorized access
- ▪On August 7, 2026, BTCPay Server warned users of a critical vulnerability under active exploit that could result in the loss of funds
- ▪BTCPay Server founder Nicolas Dorier released version 2.4.2 on August 7, 2026, and instructed integrators to also upgrade the NBXplorer wallet-tracking backend to version 2.6.10
- ▪BTCPay Server founder Nicolas Dorier clarified that the actively exploited critical vulnerability is not the Greenfield API two-factor authentication bypass bug disclosed in the version 2.4.2 changelog
- ▪BTCPay Server advised users to replace credential files known as macaroons, recreate the macaroons.db file, refresh authentication strings, and move funds from hot on-chain wallets
Lightning node fund drains
- ▪The pseudonymous bitcoin commentator hodlonaut reported that the Lightning node for the zine Citadel21 was swept by attackers during the BTCPay Server exploit on August 7, 2026
- ▪Foundation Chief Executive Officer Zach Herbert confirmed that the company's BTCPay Server Lightning node was drained overnight prior to August 7, 2026, though its hot wallet remained untouched
- ▪Attackers actively drained Lightning nodes belonging to BTCPay Server users, including nodes operated by hardware wallet maker Foundation and the bitcoin zine Citadel21, before the public alert was issued on August 7, 2026
Craig Raw vulnerability discovery
- ▪BTCPay Server founder Nicolas Dorier credited Sparrow Wallet developer Craig Raw with discovering the critical vulnerability by analyzing logs after losing money to the exploit
- ▪BTCPay Server core contributor Uncle Rockstar stated that the project is working with the Bitcoin Red Team to process the vulnerability details and will publish a detailed technical post
AI security scanning limitations
- ▪The failure of AI scans to detect the BTCPay Server vulnerability occurred despite the Bitcoin Red Team's recent efforts running AI-assisted audits across bitcoin's open-source stack
- ▪Nicolas Dorier stated that the Bitcoin Red Team's AI-assisted security scans missed the critical vulnerability because the bug was highly sneaky and difficult for a simple scan to detect
Self-hosted software patch challenges
- ▪Security experts warned that upgrading BTCPay Server alone does not secure a node if attackers already copied credential macaroons prior to the patch, as stolen credentials remain valid until destroyed
- ▪The BTCPay Server exploit occurred during a period of multiple bitcoin infrastructure security failures, including a Coldcard firmware bug causing $114 million in losses and a service halt by swap bridge Boltz
- ▪Because BTCPay Server is a self-hosted, open-source payment processor, individual merchants and operators must manually apply the software patch on their own machines
Story comments
Loading comments…