Critical BTCPay Lightning Vulnerability Drains Funds from Nodes
A vulnerability in BTCPay Server allowed attackers to take full control of Lightning Network nodes without authentication, resulting in drained funds. Affected configurations include those using LND.
A critical vulnerability in BTCPay Server enabled attackers to gain full unauthorized control over Lightning Network nodes, leading to the draining of funds from multiple affected nodes. The exploit targeted configurations running LND (Lightning Network Daemon), a popular Lightning implementation.
Among the known victims are hardware wallet manufacturer Foundation and Bitcoin publication Citadel21. Both entities reportedly had their Lightning nodes emptied as a result of the exploit.
BTCPay developers have urged all users to immediately update to version 2.4.2 or, if that is not feasible, to disable their Lightning server until the patch is applied. No further technical details about the exploit were disclosed in the original alert.
Source: ForkLog