Attackers exploited a critical vulnerability in BTCPay Server, emptying Lightning nodes tied to the self-hosted bitcoin payment processor. The incident, disclosed Aug. 7, 2026, prompted an urgent notice from BTCPay Server and immediate calls for users to update their software.
The flaw allowed attackers to access and drain Lightning nodes without separately breaching a user's hot wallet. BTCPay Server confirmed active exploitation in a notice posted at 11:51 a.m. ET, warning of potential fund loss and urging immediate updates or server shutdowns.
Hardware wallet maker Foundation and bitcoin zine Citadel21 reported drained nodes hours before BTCPay Server's public alert. Zach Herbert, CEO of Foundation, said his company's Lightning node was swept overnight, though its hot wallet remained untouched. All channels were closed and funds were moved.
hodlonaut, the pseudonymous operator behind Citadel21, reported a similar pattern. The zine's Lightning node was swept, though hodlonaut said the funds at stake were not significant. Other operators also described closed channels and drained balances in response to the public warning.
BTCPay Server founder Dorier released version 2.4.2 the same morning to address the vulnerability. Integrators also received instructions to upgrade NBXplorer, BTCPay's wallet-tracking backend, to version 2.6.10.
Version 2.4.2 patches the bug and regenerates macaroons—authentication tokens used by Lightning nodes. The update also rate-limits public invoice creation on payment requests and marks nine controller methods across five files as non-routable, closing endpoints that were unintentionally accessible over HTTP.
The vulnerability was not detected by automated security scanning tools and came to light only after users experienced thefts.
Dorier credited Craig Raw, the developer behind Sparrow Wallet, with assembling the details of the attack after Raw's own funds were affected. BTCPay Server also credited Raw and the Bitcoin Red Team fund for reporting the issue.
BTCPay Server supporters have offered a bounty of up to 3 BTC for the recovery of stolen funds. The project said artificial intelligence may have been used in the exploitation of the vulnerability.
No aggregate tally of affected nodes or total bitcoin lost has been published. Neither Herbert nor hodlonaut disclosed specific amounts drained from their respective Lightning nodes.

