business

BTCPay Server Locks Down Remote Lightning Access After Fund Thefts

Summarized from Cointelegraph

BTCPay Server restricted remote Lightning node access after attackers drained funds from operators including Foundation and Citadel21.

BTCPay Server has moved to restrict remote Lightning Network access following a series of attacks that successfully drained funds from node operators, with Bitcoin infrastructure providers Foundation and Citadel21 among the confirmed victims. The open-source payment processor acted swiftly after the breaches came to light, limiting the remote access vector that attackers appear to have exploited. The full scope of losses and the total number of affected operators remain unknown.

Foundation and Citadel21 publicly reported that their Lightning nodes had been emptied, drawing attention to what appears to be a targeted campaign against BTCPay-connected infrastructure. The disclosures signal that sophisticated actors were aware of a weakness in how BTCPay Server's remote Lightning configuration could be leveraged to move funds without authorization.

Read more China's C919 Completes First International Flight in Duopoly Challenge →

The incident highlights the persistent security risks facing operators who run self-hosted Bitcoin payment infrastructure, particularly when remote management features are exposed. Lightning Network nodes hold live bitcoin in payment channels, making them attractive targets for attackers who can gain even brief unauthorized access. The absence of a confirmed total loss figure suggests investigators and developers are still working to determine the full breadth of the compromise.

BTCPay Server is widely used by merchants and individuals seeking a non-custodial, open-source solution for accepting Bitcoin payments. The platform's decision to restrict the exploited remote access feature represents a defensive measure while a more permanent fix or guidance is presumably developed. Node operators running BTCPay with remote Lightning access enabled are urged to review their configurations immediately.

Continue reading at Cointelegraph.

Frequently Asked Questions

Q.Which organizations reported stolen funds in the BTCPay Lightning attack?

Foundation and Citadel21 both publicly reported that their Lightning nodes had been drained by attackers exploiting BTCPay Server's remote access feature.

Q.How much money was stolen in the BTCPay Server Lightning attack?

The total amount stolen and the number of affected node operators remain unknown as of the initial reports.

Q.What did BTCPay Server do in response to the Lightning Network attacks?

BTCPay Server restricted remote Lightning Network access after the attacks were disclosed, acting as a defensive measure to prevent further exploitation of the vulnerability.

More in business →