BTCPay Server has temporarily disabled public remote access to Lightning nodes running Lightning Network Daemon on Docker deployments after attackers exploited a critical flaw to steal credentials and move funds. The change cuts off external wallet connections made through a BTCPay Server domain or Tor onion address, including setups used by apps such as Zeus.

The project said Lightning payments can still be processed and that remote access will be restored only when it is considered safe. BTCPay also released version 2.4.2, which installs LND 0.21.1 and automatically rotates affected credentials on standard installations.

What the vulnerability exposed

BTCPay said the issue let an unauthenticated remote attacker obtain LND “macaroon” files, the credentials used to control a node. With those files, an attacker could take over an LND instance and transfer its funds.

Because of that risk, the project restricted remote connections to LND nodes exposed through BTCPay-managed access paths on Docker deployments. The temporary block affects public connections through a server domain or Tor onion service, rather than the ability of the node to keep handling Lightning payments.

What version 2.4.2 changes

In its security advisory, BTCPay said version 2.4.2 upgrades affected systems to LND version 0.21.1 and regenerates macaroon credentials automatically for standard BTCPay installations. That means operators using the default setup should receive fresh Lightning credentials as part of the update.

The project nevertheless urged operators to review their nodes for signs of compromise. It specifically pointed to unauthorized payments, unexpected channel closures, unknown peers and any mismatch between internal records and either onchain or Lightning balances.

Operators with custom access still have extra work

BTCPay warned that the automatic protection does not cover every deployment. Operators who expose LND through their own reverse proxy, a separate Tor service, a forwarded port or any route managed outside BTCPay must rotate their credentials on their own.

The project said applying the update does not shut down independently configured access paths. In those cases, administrators need to treat external exposure as still active until they change the credentials and secure the route themselves.

Reported losses and the next step

At least two operators said they were hit. Foundation CEO Zach Herbert said the company’s Lightning node was drained overnight, later adding that its hot wallet was not affected even though the Lightning channels were closed and funds were swept. Bitcoin publication Citadel21 also said its Lightning node had been swept, though neither disclosed the amount lost.

For now, BTCPay’s confirmed next step is to keep the remote-access restriction in place until the team judges it safe to restore. In the meantime, operators are being told to update, verify balances and channel activity, and rotate credentials wherever LND was exposed outside the standard BTCPay setup.

Source: cointelegraph.com