BTCPay Patch: LND Credential Flaw Exposed After Lightning Wallet Drain

BTCPay Server Patches Critical LND Credential Bug After Lightning Wallet Drain
BTCPay Server has issued a security patch after a critical bug exposed Lightning Network Daemon (LND) credentials and led to a Lightning wallet being drained. The incident centered on how sensitive authentication data could be accessed in certain configurations, allowing an attacker to connect to an LND instance and spend funds.
BTCPay Server is an open-source Bitcoin payment processor that many merchants and self-hosters use to accept Bitcoin payments, including via the Lightning Network. In typical setups, BTCPay Server can integrate with LND to manage Lightning invoices and payments, which requires storing or referencing LND connection details and credentials.
According to the information provided, the vulnerability involved the exposure of LND credentials—effectively the keys needed to control a Lightning node through its interface. Once those credentials were obtained, the attacker was able to initiate payments and drain the Lightning wallet.
BTCPay Server responded by releasing a patch to address the credential exposure issue. Security fixes of this kind are particularly important for infrastructure software like payment servers, where a single misconfiguration or leak can translate directly into loss of funds.
The episode highlights a broader reality of Lightning and self-hosted payments: while tools like BTCPay Server reduce reliance on custodians, they also place more responsibility on operators to keep systems updated and protect access to node credentials. In Lightning, possession of administrative credentials can be functionally equivalent to control over spending.
BTCPay Server’s patch underscores the need for prompt security updates across the Bitcoin and Lightning stack, especially for systems that bridge web-facing applications and wallet infrastructure.
