← Back

Wire · regulatory

BTCPay Server Patches Critical LND Credential Bug After Lightning Wallet Drain

Published

11 August 2026

Topic

regulatory

◆ Sectors

Crypto & Web3Cybersecurity

◆ Source

Read at tradingview.com →

◆ Verified

Fusion42 · 23 August 2026 · Fusion42 review

BTCPay Server released version 2.4.2 to fix a critical bug exposing LND macaroon credentials, which attackers exploited to drain merchant Lightning wallets. The patch addresses a server-side security flaw, and a recovery bounty offers up to 3 BTC as an incentive to recover stolen funds.

This Wire brief sits within Fusion42's coverage of Crypto & Web3 and Cybersecurity, and 3 sources have reported it between 8 Aug 2026 and 11 Aug 2026.

◆ ◆ The Wire takeaway

You must update your BTCPay Server immediately to avoid credential theft threatening your Lightning wallet funds. Ignoring this patch leaves your self-hosted payment setup dangerously exposed to theft.

◆ Coverage

3 sources · first reported 8 Aug 2026 · latest 11 Aug 2026

◆ Related on Wire

◆ Topics

Crypto & Web3Cybersecuritybitcoinlightning-networksecurity-patchwallet-exploitbounty