BTCPay Server Patches Critical LND Credential Bug After Lightning Wallet Drain

BTCPay Server released version 2.4.2 to fix a critical vulnerability that exposed LND credential files to unauthenticated remote access, after attackers exploited the flaw to drain merchant Lightning wallets.

BTCPay Server released version 2.4.2 to patch a critical vulnerability that let attackers remotely access LND credential files without authentication. Exploiting this bug, hackers drained merchant Lightning wallets. The update closes the security hole.