← Back

Wire · regulatory

BTCPay Server Patches Critical LND Credential Bug After Lightning Wallet Drain

Published

11 August 2026

Topic

regulatory

Sectors

Crypto & Web3Cybersecurity

Source

Read at tradingview.com

Verified

Fusion42 · 23 August 2026 · Fusion42 review

BTCPay Server released version 2.4.2 to fix a critical bug exposing LND macaroon credentials, which attackers exploited to drain merchant Lightning wallets. The patch addresses a server-side security flaw, and a recovery bounty offers up to 3 BTC as an incentive to recover stolen funds.

This Wire brief sits within Fusion42's coverage of Crypto & Web3 and Cybersecurity.

◆ The Wire takeaway

You must update your BTCPay Server immediately to avoid credential theft threatening your Lightning wallet funds. Ignoring this patch leaves your self-hosted payment setup dangerously exposed to theft.

Coverage

1 source · 11 Aug 2026

Related on Wire

Topics

Crypto & Web3Cybersecuritybitcoinlightning-networksecurity-patchwallet-exploitbounty