BTCPay just patched a critical bug. The real risk was merchant login keys.
This wasn't a private-key story first. It was a server credential story, and that's where Bitcoin payment security is moving.

CryptoVibe Desk · bitcoin · btcpay · lightning

- →BTCPay Server released version 2.4.2 after saying a critical bug was being actively used against merchants.
- →Reports say attackers accessed LND macaroon credentials and drained Lightning nodes connected to BTCPay Server.
- →Watch the postmortem for affected-user counts, stolen bitcoin, and whether Basic authentication was the real failure path.
- BTCPay Server → BTCPay Server is open-source software merchants use to accept bitcoin payments without a payment company in the middle.
- Lightning node → A Lightning node sends and receives faster bitcoin payments through payment channels.
- macaroon credentials → Macaroon credentials are permission files that let an app control parts of an LND Lightning node.
BTCPay just shipped version 2.4.2. The release says it fixes a critical vulnerability that was actively exploited. It also tells integrators to update NBXplorer to 2.6.10.
The important part is the failure mode. Reports from CoinDesk and Crypto Briefing say attackers used the bug to reach LND macaroon credentials. Those credentials can let software control a Lightning node. If you're running merchant infrastructure, your bag now depends on server hygiene, not only private-key custody.
At the contract level, there is no contract here. That's the point. Bitcoin payment security often gets discussed as key storage and signing policy. This incident points at the operational layer: web auth, API access, credential files, and what a connected service can touch.
CoinDesk reports standard BTCPay on-chain wallets were not affected. Funds inside LND's own on-chain wallet can still be at risk, according to the same report. Foundation and Citadel21 were among reported victims. BTCPay has not said how many users were hit or how much bitcoin was stolen.
Read the release notes, not the thread. The patch disables Greenfield Basic authentication by default five minutes after account creation. It also fixes a TOTP two-factor bypass tied to Greenfield Basic authentication. The engineers know this is an auth boundary problem.
The open question is blast radius. Until BTCPay publishes the postmortem, this is officially an incomplete incident report with a serious patch attached.
BTCPay's choice to leave Greenfield Basic authentication open after setup was reckless because one stale credential path could bypass two-factor checks and expose Lightning funds.
By August 15, watch whether BTCPay publishes a postmortem with affected-user counts, stolen-bitcoin estimates, and a CVE for the auth path.
Primary links and supporting reads used by the desk for this story.
Forward this.











